2018-04-30 20:13:48 +02:00
|
|
|
location __PATH__/ {
|
2016-03-23 19:30:43 +01:00
|
|
|
# Path to source
|
2017-07-03 21:07:56 +02:00
|
|
|
alias __FINALPATH__/;
|
2016-03-23 19:30:43 +01:00
|
|
|
if ($scheme = http) {
|
|
|
|
rewrite ^ https://$server_name$request_uri? permanent;
|
|
|
|
}
|
2016-06-05 20:57:07 +02:00
|
|
|
|
|
|
|
# Add headers to serve security related headers
|
|
|
|
add_header Strict-Transport-Security "max-age=15768000;";
|
|
|
|
add_header X-Content-Type-Options nosniff;
|
|
|
|
add_header X-Frame-Options "SAMEORIGIN";
|
|
|
|
add_header X-XSS-Protection "1; mode=block";
|
|
|
|
add_header X-Robots-Tag none;
|
|
|
|
add_header X-Download-Options noopen;
|
|
|
|
add_header X-Permitted-Cross-Domain-Policies none;
|
|
|
|
|
|
|
|
# Set max upload size
|
2017-07-03 21:07:56 +02:00
|
|
|
client_max_body_size __FILESIZE__;
|
2017-03-20 19:08:15 +01:00
|
|
|
client_body_timeout 30m;
|
|
|
|
proxy_read_timeout 30m;
|
2016-06-05 20:57:07 +02:00
|
|
|
fastcgi_buffers 64 4K;
|
|
|
|
|
|
|
|
# Disable gzip to avoid the removal of the ETag header
|
|
|
|
gzip off;
|
2016-04-04 21:29:46 +02:00
|
|
|
|
2016-03-23 19:30:43 +01:00
|
|
|
index index.php;
|
|
|
|
try_files $uri $uri/ index.php;
|
|
|
|
location ~ [^/]\.php(/|$) {
|
2016-06-05 20:57:07 +02:00
|
|
|
include fastcgi_params;
|
2016-03-23 19:30:43 +01:00
|
|
|
fastcgi_split_path_info ^(.+?\.php)(/.*)$;
|
2017-07-03 21:07:56 +02:00
|
|
|
fastcgi_pass unix:/var/run/php5-fpm-__NAME__.sock;
|
2016-03-23 19:30:43 +01:00
|
|
|
fastcgi_index index.php;
|
|
|
|
fastcgi_param REMOTE_USER $remote_user;
|
|
|
|
fastcgi_param PATH_INFO $fastcgi_path_info;
|
|
|
|
fastcgi_param SCRIPT_FILENAME $request_filename;
|
2016-06-05 20:57:07 +02:00
|
|
|
fastcgi_param HTTPS on;
|
|
|
|
fastcgi_param modHeadersAvailable true;
|
|
|
|
fastcgi_intercept_errors on;
|
2016-03-23 19:30:43 +01:00
|
|
|
}
|
|
|
|
|
2016-04-24 17:17:44 +02:00
|
|
|
location ~ (uploads|thumbs){
|
|
|
|
deny all;
|
|
|
|
}
|
|
|
|
|
2016-04-26 19:01:01 +02:00
|
|
|
location ~ private {
|
|
|
|
deny all;
|
|
|
|
location ~* /temp/.*\.zip$ {
|
|
|
|
allow all;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
location ~ core {
|
|
|
|
deny all;
|
|
|
|
location ~* \.js$ {
|
|
|
|
allow all;
|
|
|
|
}
|
|
|
|
}
|
2016-03-24 20:10:52 +01:00
|
|
|
|
2016-03-23 19:30:43 +01:00
|
|
|
# Include SSOWAT user panel.
|
|
|
|
include conf.d/yunohost_panel.conf.inc;
|
|
|
|
}
|