mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-10-11 05:12:10 +02:00
Webtrees: stop serving data/ and the source folders directly (#17724)
Caddy served all of /opt/webtrees through file_server, so media under data/media could be fetched by URL without passing webtrees' privacy rules. webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the folders webtrees' own nginx guide keeps private, plus dotfiles. update_script adds the rule to existing Caddyfiles on every update, not only when a new release is out, and keeps the old file if the result fails caddy validate.
This commit is contained in:
committed by
GitHub
parent
69bbf389f3
commit
36078aa896
@@ -36,6 +36,9 @@ PHP_SOCK=$(get_php_fpm_socket)
|
||||
cat <<EOF >/etc/caddy/Caddyfile
|
||||
:80 {
|
||||
root * /opt/webtrees
|
||||
# Caddy ignores data/.htaccess; media must go through webtrees so its privacy rules apply.
|
||||
@private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*
|
||||
respond @private 403
|
||||
php_fastcgi unix/${PHP_SOCK}
|
||||
file_server
|
||||
encode gzip
|
||||
|
||||
Reference in New Issue
Block a user