# Cloudflare Pages response headers for static assets.
#
# Applies only to files Pages serves itself. Responses a Pages Function
# returns don't get these, so functions-lib/render.js sets the same `/*`
# headers on the pages its Functions serve (SECURITY_HEADERS there) — keep
# the two in sync.
#
# No Content-Security-Policy yet: one that doesn't break the map (Leaflet
# tile servers, OpenStreetMap iframes) and the optional analytics script
# needs testing against each of them first.

# Vite's build output: every file under /assets/ has a content hash in its
# name, so a changed file is always a new URL and the old one can be cached
# forever.
/assets/*
  Cache-Control: public, max-age=31536000, immutable

/*
  X-Content-Type-Options: nosniff
  Referrer-Policy: strict-origin-when-cross-origin
  X-Frame-Options: DENY
