nginx vererbt add_header nicht in Blöcke, die eigene add_header setzen. Dadurch gingen X-Frame-Options, X-Content-Type-Options und X-XSS-Protection ausgerechnet bei den HTML-Antworten verloren – jeder location-Block mit Cache-Control hat sie stillschweigend abgeschaltet. Verifiziert: nginx -t ist für alle drei Konfigurationen erfolgreich. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| public | ||
| src | ||
| .dockerignore | ||
| .env.example | ||
| Dockerfile | ||
| index.html | ||
| nginx.conf | ||
| package-lock.json | ||
| package.json | ||
| vite.config.js | ||