From 6b6cf90a187b7f48f7a7e84d97689bae2df3f4cc Mon Sep 17 00:00:00 2001 From: Alexandre Aubin Date: Sun, 25 Oct 2020 11:54:32 +0100 Subject: [PATCH] Update nginx.conf to protect against path traversal issue --- conf/nginx.conf | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/conf/nginx.conf b/conf/nginx.conf index 4dee572..bf3b225 100644 --- a/conf/nginx.conf +++ b/conf/nginx.conf @@ -27,7 +27,8 @@ log_not_found off; } - location __PATH__ { + #sub_path_only rewrite ^__PATH__$ __PATH__/ permanent; + location __PATH__/ { alias __FINALPATH__/public/; proxy_hide_header ETag;