nginx: Moved dot-file-exclution from global snippet to root snippet

Only file based servers may require this directive,
other servers are not expected to leak hidden files other than on purpose
dehydrated
Felix Stupp 4 years ago
parent cca87f6425
commit debbcb1a1b
Signed by: zocker
GPG Key ID: 93E1BD26F6B02FB7

@ -1,14 +1,5 @@
include {{ nginx_snippets_directory }}/acme;
# Do not serve hidden files except
# - well-known as common web standard
# - files prefixed with file because Nextcloud requires these locations for uploading files
location ~ /\.(?!well-known)(?!file).* {
log_not_found off;
access_log off;
return 404;
}
location = /robots.txt {
allow all;
log_not_found off;

@ -1 +1,10 @@
include {{ nginx_snippets_directory }}/global;
# Do not serve hidden files except
# - well-known as common web standard
# - files prefixed with file because Nextcloud requires these locations for uploading files
location ~ /\.(?!well-known)(?!file).* {
log_not_found off;
access_log off;
return 404;
}

Loading…
Cancel
Save