Operations

Security

AstroGuide's actual scope, HTTP headers and safe exposure practices.

AstroGuide is a static application without a backend, user accounts or API keys. The relevant attack surface is the dependency chain, Docker image, GitHub Actions workflows, HTTP headers and browser.

Container headers

nginx.conf sends, among others:

  • X-Content-Type-Options: nosniff
  • Referrer-Policy: no-referrer
  • Permissions-Policy: camera=(), geolocation=(), microphone=()
  • a CSP restricted to 'self', with img-src allowing data: and blob:, and style-src allowing 'unsafe-inline'

server_tokens is disabled and the Nginx process does not run as root.

Vercel demo headers

The product's vercel.json applies an equivalent CSP, plus X-Robots-Tag: noindex, nofollow, noarchive and frame-ancestors 'none'.

Recommendations

AstroGuide has no JWT, session cookie or secret environment variable to rotate.