From add51eb5221ab39c8dad2eb8b1ff55fb4476c4e5 Mon Sep 17 00:00:00 2001 From: Jakob Ankarhem Date: Mon, 8 Jun 2026 18:15:35 +0200 Subject: [PATCH] feat: disable CSP in favour of nginx response header (#2) * feat: disable CSP in favour of nginx response header The CSP is now served as an HTTP response header by nginx (nix-config modules/blog.nix) so Cloudflare can parse a per-request nonce and stamp it onto the scripts it injects at the edge. A CSP cannot carry a nonce and would co-enforce alongside the header, re-blocking those scripts. * docs: explain why CSP is disabled --- zola.toml | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/zola.toml b/zola.toml index 196a7fb..735c837 100644 --- a/zola.toml +++ b/zola.toml @@ -40,11 +40,11 @@ socials = [ { name = "mastodon", url = "https://mastodon.social/@jakobankarhem" }, ] +# CSP is served as an HTTP response header by nginx (see nix-config +# modules/blog.nix), not as a tag. This is required so Cloudflare's +# JavaScript Detections can parse the per-request nonce from the header and +# stamp it onto the inline scripts it injects at the edge (whose hashes change +# every request and cannot be pinned). A CSP cannot carry a nonce and +# would co-enforce alongside the header, re-blocking the injected scripts. [extra.content_security_policy] -enable = true -allowed_domains = [ - { directive = "base-uri", domains = ["'self'"] }, - { directive = "connect-src", domains = ["'self'", "cloudflareinsights.com"] }, - { directive = "form-action", domains = ["'self'"] }, - { directive = "script-src", domains = ["'self'", "static.cloudflareinsights.com", "'sha512-8DS7rgIrAmghBFwoOTujcf6D9rXvH8xm8JQ1Ja01h9QX8EzXldiszufYa4IFfKdLUKTTrnSFXLDkUEOTrZQ8Qg=='"] }, -] +enable = false -- 2.51.2