Compare commits

..

1 Commits

Author SHA1 Message Date
Ivan Gabaldon
d31bc8efaa Merge a99c06801d into 271ba86644 2025-01-03 10:37:01 +01:00
2 changed files with 21 additions and 36 deletions

View File

@@ -33,21 +33,20 @@ encode zstd gzip
path /stats/checker path /stats/checker
} }
@search { @static {
path /search path /static/*
} }
@imageproxy { @imageproxy {
path /image_proxy path /image_proxy
} }
@static {
path /static/*
}
header { header {
# CSP (https://content-security-policy.com) # Force clients to use HTTPS
Content-Security-Policy "upgrade-insecure-requests; default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; form-action 'self' https://github.com/searxng/searxng/issues/new; font-src 'self'; frame-ancestors 'self'; base-uri 'self'; connect-src 'self' https://overpass-api.de; img-src * data:; frame-src https://www.youtube-nocookie.com https://player.vimeo.com https://www.dailymotion.com https://www.deezer.com https://www.mixcloud.com https://w.soundcloud.com https://embed.spotify.com;" Strict-Transport-Security "max-age=31536000"
# Prevent MIME type sniffing from the declared Content-Type
X-Content-Type-Options "nosniff"
# Disable some browser features # Disable some browser features
Permissions-Policy "accelerometer=(),camera=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),payment=(),usb=()" Permissions-Policy "accelerometer=(),camera=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),payment=(),usb=()"
@@ -55,12 +54,6 @@ header {
# Set referrer policy # Set referrer policy
Referrer-Policy "no-referrer" Referrer-Policy "no-referrer"
# Force clients to use HTTPS
Strict-Transport-Security "max-age=31536000"
# Prevent MIME type sniffing from the declared Content-Type
X-Content-Type-Options "nosniff"
# X-Robots-Tag (comment to allow site indexing) # X-Robots-Tag (comment to allow site indexing)
X-Robots-Tag "noindex, noarchive, nofollow" X-Robots-Tag "noindex, noarchive, nofollow"
@@ -74,11 +67,13 @@ header @api {
} }
route { route {
# Cache policy # Caching
header Cache-Control "max-age=0, no-store" header Cache-Control "no-cache, no-store"
header @search Cache-Control "max-age=5, private" header @static Cache-Control "public, max-age=31536000"
header @imageproxy Cache-Control "max-age=604800, public"
header @static Cache-Control "max-age=31536000, public, immutable" # CSP (https://content-security-policy.com)
header Content-Security-Policy "upgrade-insecure-requests; default-src 'none'; script-src 'self'; style-src 'self' 'unsafe-inline'; form-action 'self' https://github.com/searxng/searxng/issues/new; font-src 'self'; frame-ancestors 'self'; base-uri 'self'; connect-src 'self' https://overpass-api.de; img-src 'self' data: https://*.tile.openstreetmap.org; frame-src https://www.youtube-nocookie.com https://player.vimeo.com https://www.dailymotion.com https://www.deezer.com https://www.mixcloud.com https://w.soundcloud.com https://embed.spotify.com"
header @imageproxy Content-Security-Policy "default-src 'none'; img-src 'self' data:"
} }
# SearXNG (uWSGI) # SearXNG (uWSGI)

View File

@@ -61,24 +61,14 @@ To access the logs of one specific container:
### Start SearXNG with systemd ### Start SearXNG with systemd
You can skip this step if you don't use systemd. You can skip this step if you don't use systemd.
1. Copy the service template file:
```sh
cp searxng-docker.service.template searxng-docker.service
```
2. Edit the content of ```WorkingDirectory``` in the ```searxng-docker.service``` file (only if the installation path is different from ```/usr/local/searxng-docker```) - ```cp searxng-docker.service.template searxng-docker.service```
- edit the content of ```WorkingDirectory``` in the ```searxng-docker.service``` file (only if the installation path is different from /usr/local/searxng-docker)
3. Enable the service: - Install the systemd unit:
```sh ```sh
systemctl enable $(pwd)/searxng-docker.service systemctl enable $(pwd)/searxng-docker.service
``` systemctl start searxng-docker.service
```
4. Start the service:
```sh
systemctl start searxng-docker.service
```
**Note:** Ensure the service file path matches your installation directory before enabling it.
## Note on the image proxy feature ## Note on the image proxy feature