Three layers, each tested. Report issues via
/.well-known/security.txt (private GitHub reporting is enabled).
- Static assets:
public/_headers(/*block). Function-rendered HTML: rootfunctions/_middleware.ts— a parity test fails if the two CSPs drift. - Set: CSP (self + Fonts + Turnstile,
form-action 'self'), HSTS (1y + includeSubDomains), nosniff,SAMEORIGINframing, strict referrer, locked-down Permissions-Policy. Badges/OG intentionallycross-origin. - Deliberately absent:
upgrade-insecure-requests(would break localhttp://localhostPages dev), HSTSpreload(one-way commitment), CSP nonces (needs inline-script refactor — a follow-up, not this run).
Application (see AUTHZ_MATRIX.md, T-07 secret scan)
- Sessions: stateless HMAC cookies (30d),
__Host-prefix, Secure/HttpOnly/SameSite. - SSRF boundary around every server-side fetch (redirect + metadata guards).
- No secrets in history/config;
.env.exampleis the complete key list.
The repo cannot assert dashboard state, so confirm once and re-check yearly:
- TLS mode Full (strict); Always Use HTTPS on; HSTS dashboard toggle matches the header (or off, since the header carries it).
- WAF: managed ruleset on; custom rule throttling
POST /api/scan(e.g. >20/min/IP → challenge) as backstop to the in-code limiter. - Bots: Bot Fight Mode (or better) on; Turnstile widget key matches
TURNSTILE_SITEKEYinwrangler.toml. - Private vulnerability reporting stays enabled (repo Settings → Security → Private vulnerability reporting).
-
security.txtExpires stays >30d out — the suite fails otherwise.