michael,
@michael@thms.uk avatar

Re 4.1.3: The release notes recommend:

“The recommended configuration for reverse proxies has been updated. [...] The change is about setting Content-Security-Policy: default-src 'none'; form-action 'none' and X-Content-Type-Options: nosniff on assets.”

This might be a bit confusing, because of the terminology:

Those two lines ought to to into the location ~ ^/system/ block - NOT location ~ ^/assets/

https://github.com/mastodon/mastodon/pull/25756/commits/8060ab945392b2fa88d75a49a09a4c5895e72f71

kikobar,
@kikobar@acc4e.com avatar

@michael not sure I understand.

Those changes are in the system block and not the assets block, however they are already included in the tag v4.1.3, so in reality we don't need to do anything besides fetching the code and checking out the tag v4.1.3, correct?

michael,
@michael@thms.uk avatar

@kikobar no, because the file included in the repo isn’t copied into your nginx configuration during update (or at any other time, really).

You need to copy and paste these two lines into your mastodon nginx config (unless you are proxying your media files, in which case you need to do something else)

kikobar,
@kikobar@acc4e.com avatar

@michael got it. Thanks!

  • All
  • Subscribed
  • Moderated
  • Favorites
  • mastodon
  • kavyap
  • thenastyranch
  • tester
  • GTA5RPClips
  • InstantRegret
  • DreamBathrooms
  • ngwrru68w68
  • magazineikmin
  • everett
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • cisconetworking
  • megavids
  • khanakhh
  • normalnudes
  • osvaldo12
  • cubers
  • tacticalgear
  • Durango
  • ethstaker
  • modclub
  • anitta
  • provamag3
  • Leos
  • JUstTest
  • lostlight
  • All magazines