1# aldebaran-headers
2
3The headers every response of a site carries, in one place so a response
4cannot leave without them. Whiskers had them by hand; the other sites sent
5none.
6
7| Item | What it is |
8|---|---|
9| `Policy::own_origin_only()` | The starting point: the site itself and nothing else, no eval, no inline script, no `data:` images, no framing, no forms. |
10| `.for_datastar()` | Adds `'unsafe-eval'`, which Datastar needs (it compiles each `data-*` expression with `new Function`). |
11| `.with_inline_styles()`, `.with_data_images()`, `.with_inline_script()` | One named widening each. |
12| `.allow_origin("https://host")` | One other origin. Refuses a wildcard, a bare scheme, a path, `http`. |
13| `.headers()` | Name and value pairs: the policy, `nosniff`, `no-referrer`, a permissions policy, same-origin opener. |
14| `html_cache_control(seconds)` | The only HTML cache header: always `no-transform`, so Cloudflare does not add its analytics script. |