Repository navigation
Expand file tree
/
Copy path.htaccess
More file actions
18 lines (17 loc) · 1.66 KB
/
Copy path.htaccess
File metadata and controls
18 lines (17 loc) · 1.66 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
# SECURITY: Content Security Policy & HSTS
<IfModule mod_headers.c>
# Content Security Policy — audited against all external resources in index.html
# Includes Google Auth (accounts.google.com, apis.google.com, oauth2.googleapis.com)
# and all existing CDNs (Tailwind, cdnjs, esm.sh, Gemini, Google Fonts)
Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.tailwindcss.com https://cdnjs.cloudflare.com https://esm.sh https://accounts.google.com https://apis.google.com; style-src 'self' 'unsafe-inline' https://cdnjs.cloudflare.com https://fonts.googleapis.com https://accounts.google.com; font-src 'self' https://fonts.gstatic.com https://cdnjs.cloudflare.com; img-src 'self' data: blob: https://*.rawgraded.com https://assets.rawgraded.com https://api.qrserver.com https://lh3.googleusercontent.com; connect-src 'self' https://esm.sh https://generativelanguage.googleapis.com https://accounts.google.com https://oauth2.googleapis.com https://api.pokemontcg.io https://api.tcgdex.net; frame-src https://accounts.google.com; base-uri 'self'; object-src 'none'; form-action 'self' https://accounts.google.com; upgrade-insecure-requests;"
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
Header set X-Content-Type-Options "nosniff"
Header set X-Frame-Options "SAMEORIGIN"
Header set X-XSS-Protection "1; mode=block"
Header set Referrer-Policy "strict-origin-when-cross-origin"
Header always unset X-Powered-By
Header always unset Server
</IfModule>