| Server IP : 35.80.110.71 / Your IP : 216.73.216.221 Web Server : Apache/2.4.58 (Ubuntu) System : Linux ip-172-31-21-44 6.17.0-1019-aws #19~24.04.1-Ubuntu SMP Tue Jun 23 18:53:06 UTC 2026 x86_64 User : ubuntu ( 1000) PHP Version : 8.3.31 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : ON | Perl : ON | Python : OFF | Sudo : ON | Pkexec : OFF Directory : /var/www/codex/shared/apache/ |
Upload File : |
# CSP for api.codex.philiprehberger.com, EXCLUDING /admin.
#
# The api host serves JSON only outside /admin. CSP is mostly
# precautionary since there's no UI to inject into — but the same
# headers stop a hypothetical RFC 7807 problem-detail body from
# triggering script execution via a malformed user agent.
#
# /admin is Filament UI with inline scripts; csp-admin.conf wires
# the nonce-based CSP via AdminCspMiddleware (Phase 3).
<IfModule mod_headers.c>
# Skip /admin — AdminCspMiddleware emits a per-request nonce CSP there.
<LocationMatch "^/(?!admin)">
Header always set Content-Security-Policy "default-src 'none'; frame-ancestors 'none'; base-uri 'self'"
</LocationMatch>
</IfModule>