From e1b5eead3f24535e4825ac080edf65f5157c7623 Mon Sep 17 00:00:00 2001 From: ariasuni Date: Mon, 28 Aug 2017 16:40:50 +0200 Subject: [PATCH] [fix] disable gzip compression for json to avoid BREACH attack --- data/templates/nginx/plain/global.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/data/templates/nginx/plain/global.conf b/data/templates/nginx/plain/global.conf index a3096d009..341f08620 100644 --- a/data/templates/nginx/plain/global.conf +++ b/data/templates/nginx/plain/global.conf @@ -1,2 +1,2 @@ server_tokens off; -gzip_types text/plain text/css application/json application/javascript text/xml application/xml application/xml+rss text/javascript; +gzip_types text/plain text/css application/javascript text/xml application/xml application/xml+rss text/javascript;