diff --git a/.nginx.conf b/.nginx.conf index fdb3270..012317c 100644 --- a/.nginx.conf +++ b/.nginx.conf @@ -3,6 +3,13 @@ location / { try_files $uri $uri/ /index.php?$query_string; } +# Uncomment the following lines if you are not using a `public` directory +# to prevent sensitive resources from being exposed. +# location ~* ^/(\.git|composer\.(json|lock)|auth\.json|config\.php|flarum|storage|vendor) { +# deny all; +# return 404; +# } + # The following directives are based on best practices from H5BP Nginx Server Configs # https://github.com/h5bp/server-configs-nginx