use Log::Log4perl;
use constant AUTH_TIMEOUT => 5 * 60;
- use constant ACCESSLOG_FORMAT => '%{X-Forwarded-For}i %l %u %t "%r" %>s %b "%{Referer}i" "%{User-agent}i"';
sub CONTENT_SECURITY_POLICY () {
my $csp = <<CSP;
connect-src 'self'
form-action 'self'
frame-ancestors 'none'
-img-src 'self'
+img-src 'self' https://static.mindcoding.ro
referrer origin-when-cross-origin
-script-src 'self'
-style-src 'self'
+script-src https://static.mindcoding.ro/static/js.js
+style-src https://static.mindcoding.ro/static/css/
CSP
chomp $csp;
$csp =~ s/\n/; /gr;
my $resp = $app->($_[0]);
my $hdrs = Plack::Util::headers($resp->[1]);
$hdrs->set('Content-Security-Policy', CONTENT_SECURITY_POLICY);
- $hdrs->set('Link', '</static/cyborg.css>; rel=stylesheet') if $hdrs->get('Content-Type') =~ m,^text/html,;
+ $hdrs->set('Link', '<https://static.mindcoding.ro/static/slate.css>; rel=stylesheet') if $hdrs->get('Content-Type') =~ m,^text/html,;
$hdrs->set('Cache-Control', 'public, max-age=604800') if $_[0]->{PATH_INFO} =~ qr,^/static/,;
$resp->[1] = $hdrs->headers;
$resp;
}
Log::Log4perl->init_once('log.conf');
- my $access_logger = Log::Log4perl->get_logger('access');
$ENV{DBIC_NULLABLE_KEY_NOWARN} = 1;
builder {
enable_if { $_[0]->{PATH_INFO} eq '/ok' } sub { sub{ [200, [], []] }};
- enable 'AccessLog', format => ACCESSLOG_FORMAT, logger => sub { $access_logger->info(@_) };
enable 'ContentLength';
enable \&add_headers;
enable 'Static', path => qr,^/static/,;
-log4perl.category. = TRACE,
+log4perl.category. = TRACE, stderr
- log4perl.category.access = INFO, accesslog
log4perl.appender.stderr = Log::Log4perl::Appender::Screen
log4perl.appender.stderr.layout = Log::Log4perl::Layout::PatternLayout
log4perl.appender.stderr.layout.ConversionPattern = [%d] [%F{1}:%M{1}:%L] [%p] %m%n
-
- log4perl.appender.accesslog = Log::Log4perl::Appender::File
- log4perl.appender.accesslog.filename = /var/log/accesslog
- log4perl.appender.accesslog.layout = Log::Log4perl::Layout::PatternLayout
- log4perl.appender.accesslog.layout.ConversionPattern = %m%n