There were no security headers at all. Now:
- every response: nosniff, Referrer-Policy strict-origin-when-cross-origin,
Permissions-Policy (no camera/mic/geolocation), X-Frame-Options DENY;
each set only if the handler hasn't.
- HSTS only when the trusted proxy reports HTTPS (rule 94); never a redirect.
- index.html carries a Content-Security-Policy whose script-src is 'self'
plus the sha256 of each inline script in the page as served, computed
after the branding template runs. No 'unsafe-inline' or 'unsafe-eval'
for scripts. img-src admits remote https/http because Lidarr suggestion
art is a remote poster URL.
Hashing in Go rather than via SvelteKit's kit.csp covers the inline scripts
SvelteKit doesn't know about (app.html's theme bootstrap and the branding
global injected at build) and stays correct whatever the app name is.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
go:embed paths are relative to the source file and cannot reach parent
directories, so internal/web/embed.go could not see web/build/ without
duplicating the placeholder. Relocating to web/embed.go lets the
directive resolve to the real SvelteKit build output with no copy step.