From 0ef4318913df417d3dde5024a085b7f2c3f7804d Mon Sep 17 00:00:00 2001 From: Clark Winkelmann Date: Wed, 3 Jun 2020 08:59:10 +0200 Subject: [PATCH] nginx rule to prevent access to sensitive files (#65) * nginx rule to prevent access to sensitive files * Add a suggested rule that does the same as the suggested rule in .htaccess * Add .git and auth.json to nginx sensitive resources --- .nginx.conf | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.nginx.conf b/.nginx.conf index fdb3270..012317c 100644 --- a/.nginx.conf +++ b/.nginx.conf @@ -3,6 +3,13 @@ location / { try_files $uri $uri/ /index.php?$query_string; } +# Uncomment the following lines if you are not using a `public` directory +# to prevent sensitive resources from being exposed. +# location ~* ^/(\.git|composer\.(json|lock)|auth\.json|config\.php|flarum|storage|vendor) { +# deny all; +# return 404; +# } + # The following directives are based on best practices from H5BP Nginx Server Configs # https://github.com/h5bp/server-configs-nginx