From 7eb70802684e21adf96f8e7ff2301786b92c0a84 Mon Sep 17 00:00:00 2001 From: jraedisch Date: Wed, 13 May 2026 20:47:06 +0200 Subject: [PATCH] metadata audit fixups: security headers, twitter:card=summary, JSON-LD author Cross-property audit on 2026-05-13 flagged three gaps relative to divepool's setup: - ansible/templates/Caddyfile.j2: add security headers matching divepool's posture (HSTS preload, X-Frame-Options DENY, X-Content-Type-Options nosniff, Referrer-Policy, Permissions- Policy, -Server). Defense-in-depth even though pingarthur has no user-facing UI - homepage.go: twitter:card summary_large_image -> summary. summary_large_image expects 2:1 landscape, our og:image is 1000x1000 square so summary renders correctly. (Bluesky tolerates the mismatch; Twitter would crop.) - homepage.go: JSON-LD creator -> author. Both valid for SoftwareApplication per schema.org, but author is the preferred property and aligns with divepool's WebApplication convention OpenAPI sitemap loc deliberately kept at the bare /api/v1/openapi path so social-preview bots get the OG-tagged HTML stub; the .json suffix variant always returns raw JSON and defeats the preview. Co-Authored-By: Claude Opus 4.7 (1M context) --- ansible/templates/Caddyfile.j2 | 13 +++++++++++++ homepage.go | 4 ++-- 2 files changed, 15 insertions(+), 2 deletions(-) diff --git a/ansible/templates/Caddyfile.j2 b/ansible/templates/Caddyfile.j2 index 658c30d..3b57560 100644 --- a/ansible/templates/Caddyfile.j2 +++ b/ansible/templates/Caddyfile.j2 @@ -13,6 +13,19 @@ {{ pingarthur_domain }} { tls /etc/caddy/certs/{{ pingarthur_domain }}.crt /etc/caddy/certs/{{ pingarthur_domain }}.key + # Security headers — matches divepool.social posture. HSTS preload-eligible, + # no framing, no MIME sniffing, conservative referrer policy, no ambient + # access to camera/mic/geo (defense-in-depth even though pingarthur has no + # UI). -Server hides Caddy's banner. + header { + Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" + X-Frame-Options "DENY" + X-Content-Type-Options "nosniff" + Referrer-Policy "strict-origin-when-cross-origin" + Permissions-Policy "camera=(), microphone=(), geolocation=()" + -Server + } + # Public API endpoints + supervisor health probe + homepage. handle /api/v1/* { reverse_proxy 127.0.0.1:8080 diff --git a/homepage.go b/homepage.go index 14400ee..ea7fe36 100644 --- a/homepage.go +++ b/homepage.go @@ -27,7 +27,7 @@ const homepageHTML = ` - + @@ -42,7 +42,7 @@ const homepageHTML = ` "applicationCategory": "DeveloperApplication", "operatingSystem": "Any", "offers": {"@type": "Offer", "price": "0", "priceCurrency": "USD"}, - "creator": {"@type": "Person", "name": "Jasper Rädisch", "url": "https://raedisch.net/"}, + "author": {"@type": "Person", "name": "Jasper Rädisch", "url": "https://raedisch.net/"}, "sameAs": [ "https://bsky.app/profile/pingarthur.com", "https://tangled.org/divepool.social/pingarthur" -- 2.51.2