Fix pentest security findings
- Turnstile server-side verification: reject requests with no cf_token; read secret from TURNSTILE_SECRET_KEY env (no longer hardcoded); fix siteverify URL from v0 to v1 - Security headers: wrap all responses via http_response() with HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy, and Content-Security-Policy - GCS error info leak: guard /share/<id> response — only return content that starts with '<' (valid HTML); GCS error JSON is silently 404d - robots.txt: remove Sitemap reference to sitemap.xml that returns 404 - SRI hash: add integrity + crossorigin attributes to marked.min.js CDN tag - Attestations bucket: write /api/attest records to GCS_ATTEST_BUCKET (dedicated private bucket) instead of the share bucket; falls back to GCS_SHARE_BUCKET if GCS_ATTEST_BUCKET is not set (legacy deploys)
This commit is contained in:
+1
-1
@@ -1828,7 +1828,7 @@ fn page_open() -> String {
|
||||
button[disabled] { opacity: 0.6; cursor: not-allowed; }
|
||||
|
||||
</style>
|
||||
<script src=\"https://cdn.jsdelivr.net/npm/marked/marked.min.js\"></script>
|
||||
<script src=\"https://cdn.jsdelivr.net/npm/marked/marked.min.js\" integrity=\"sha384-948ahk4ZmxYVYOc+rxN1H2gM1EJ2Duhp7uHtZ4WSLkV4Vtx5MUqnV+l7u9B+jFv+\" crossorigin=\"anonymous\"></script>
|
||||
<script src=\"https://challenges.cloudflare.com/turnstile/v0/api.js\" async defer></script>
|
||||
<noscript><style>.reveal { opacity: 1 !important; transform: none !important; }</style></noscript>
|
||||
|
||||
|
||||
Reference in New Issue
Block a user