# Response headers for bench.12vectors.com. # # Read by Cloudflare Workers static assets at deploy time — the file is # consumed, never served — and copied here from site/root/ by # site/build.py, because the host looks for it at the root of the build # and nowhere else. # # Rules apply in order and a later rule wins on a header it repeats. The # two blocks below are written so that even a host that merged them # instead would land on the safe side: HTML would still revalidate. # Everything, so that no page can ever forget one of these. # # nosniff a text/plain file must not become a script # Referrer-Policy a full url is never sent to another origin # HSTS one year, this host and anything below it. No # `preload`: that is a submission to browser # vendors and a commitment this card did not make # X-Frame-Options nothing here is meant to be framed # CSP the runtime form of the site's own promise — # no analytics, no font CDN, no third-party # anything. `default-src 'none'` means an asset # must be named below to load at all, and no # 'unsafe-inline' anywhere means an injected #