aldebaran-headers
The headers every response of a site carries, in one place so a response cannot leave without them. Whiskers had them by hand; the other sites sent none.
| Item | What it is |
|---|---|
Policy::own_origin_only() | The starting point: the site itself and nothing else, no eval, no inline script, no data: images, no framing, no forms. |
.for_datastar() | Adds 'unsafe-eval', which Datastar needs (it compiles each data-* expression with new Function). |
.with_inline_styles(), .with_data_images(), .with_inline_script() | One named widening each. |
.allow_origin("https://host") | One other origin. Refuses a wildcard, a bare scheme, a path, http. |
.headers() | Name and value pairs: the policy, nosniff, no-referrer, a permissions policy, same-origin opener. |
html_cache_control(seconds) | The only HTML cache header: always no-transform, so Cloudflare does not add its analytics script. |