# Example complete site used for validation. Merge only the reviewed handles into # the existing forge site. Route order is security-sensitive. forge.example.invalid { encode zstd gzip @git path /git /git/* handle @git { reverse_proxy 127.0.0.1:3000 } handle_path /timmy-staging/* { basic_auth { staging {$TIMMY_STAGING_PASSWORD_HASH} } request_body { max_size 8MB } header { X-Content-Type-Options "nosniff" X-Frame-Options "DENY" Referrer-Policy "no-referrer" Permissions-Policy "camera=(self), microphone=(), geolocation=()" Content-Security-Policy "default-src 'self'; img-src 'self' data: blob:; style-src 'self'; script-src 'self'; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'none'; form-action 'self'" -Server } # handle_path strips the public prefix exactly once. Reconstruct it for # Timmy because its validated base-path router must see that same prefix. rewrite * /timmy-staging{uri} reverse_proxy 127.0.0.1:4174 } # Existing Gitea catchall belongs after the private staging route. handle { reverse_proxy 127.0.0.1:3000 } }