Proactive security & health pass. No live/exploitable vulnerabilities were found; these changes remove information-disclosure surfaces and add standard hardening. - Remove publicly-downloadable 1.1 MB full source dump (code_export.txt) and stray empty l.php; add code_export.txt to .gitignore. - Exclude dev files/folders (*.sh, *.py, docs/, templates/, tools/, README.md) from the rsync deploy so they never reach the live server. - .htaccess: add X-Frame-Options, Referrer-Policy, Permissions-Policy, and a report-only Content-Security-Policy; add defense-in-depth deny block for dev/VCS files (robots.txt & sitemap.xml left served). - .htaccess: fix root redirect to canonical msosorg.com + /en/. - Swap 4 project-page YouTube embeds to youtube-nocookie.com so no Google cookies are set before consent (GDPR). - Add rel="noopener" to 30 team social links on the About Us pages. - Harden esc() in my-route.js to also escape single quotes. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> |
||
|---|---|---|
| .gitea/workflows | ||
| css | ||
| docs | ||
| en | ||
| images | ||
| mk | ||
| si | ||
| templates | ||
| tools | ||
| .gitignore | ||
| .htaccess | ||
| 404.html | ||
| README.md | ||
| apple-touch-icon.png | ||
| blog-filter.js | ||
| consent.js | ||
| export_code.sh | ||
| favicon-96x96.png | ||
| favicon.ico | ||
| favicon.svg | ||
| guide-feedback.js | ||
| main.js | ||
| member-form.js | ||
| my-route.js | ||
| news-filter.js | ||
| optimize_images.py | ||
| robots.txt | ||
| site.webmanifest | ||
| sitemap.xml | ||
| student-guide.js | ||
| style.css | ||
| update_html.py | ||
| web-app-manifest-192x192.png | ||
| web-app-manifest-512x512.png | ||
README.md
msos spletna stran