|
@@ -3247,23 +3247,75 @@ function install_wiki {
|
3247
|
3247
|
|
3248
|
3248
|
echo 'server {' > /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3249
|
3249
|
echo ' listen 80;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3250
|
|
- echo " server_name $WIKI_DOMAIN_NAME;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3251
|
3250
|
echo " root /var/www/$WIKI_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3251
|
+ echo " server_name $WIKI_DOMAIN_NAME;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3252
|
3252
|
echo " error_log /var/www/$WIKI_DOMAIN_NAME/error.log;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3253
|
3253
|
echo ' index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3254
|
+ echo ' charset utf-8;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3255
|
+ echo ' client_max_body_size 20m;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3256
|
+ echo ' client_body_buffer_size 128k;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3254
|
3257
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3255
|
|
- echo ' # Uncomment this if you need to redirect HTTP to HTTPS' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3256
|
|
- echo ' #rewrite ^ https://$server_name$request_uri? permanent;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3257
|
|
- echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3258
|
+ echo ' # rewrite to front controller as default rule' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3258
|
3259
|
echo ' location / {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3259
|
|
- echo ' try_files $uri $uri/ /index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3260
|
+ echo ' rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3261
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3262
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3263
|
+ echo " # make sure webfinger and other well known services aren't blocked" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3264
|
+ echo ' # by denying dot files and rewrite request to the front controller' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3265
|
+ echo ' location ^~ /.well-known/ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3266
|
+ echo ' allow all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3267
|
+ echo ' rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3260
|
3268
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3261
|
3269
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3262
|
|
- echo ' location ~ \.php$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3270
|
+ echo ' # statically serve these file types when possible' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3271
|
+ echo ' # otherwise fall back to front controller' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3272
|
+ echo ' # allow browser to cache them' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3273
|
+ echo ' # added .htm for advanced source code editor library' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3274
|
+ echo ' location ~* \.(jpg|jpeg|gif|png|ico|css|js|htm|html|ttf|woff|svg)$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3275
|
+ echo ' expires 30d;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3276
|
+ echo ' try_files $uri /index.php?q=$uri&$args;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3277
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3278
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3279
|
+ echo ' # block these file types' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3280
|
+ echo ' location ~* \.(tpl|md|tgz|log|out)$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3281
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3282
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3283
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3284
|
+ echo ' # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3285
|
+ echo ' # or a unix socket' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3286
|
+ echo ' location ~* \.php$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3287
|
+ echo ' # Zero-day exploit defense.' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3288
|
+ echo ' # http://forum.nginx.org/read.php?2,88845,page=3' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3289
|
+ echo " # Won't work properly (404 error) if the file is not stored on this" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3290
|
+ echo " # server, which is entirely possible with php-fpm/php-fcgi." >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3291
|
+ echo " # Comment the 'try_files' line out if you set up php-fpm/php-fcgi on" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3292
|
+ echo " # another machine. And then cross your fingers that you won't get hacked." >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3293
|
+ echo ' try_files $uri $uri/ /index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3294
|
+ echo ' # NOTE: You should have "cgi.fix_pathinfo = 0;" in php.ini' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3263
|
3295
|
echo ' fastcgi_split_path_info ^(.+\.php)(/.+)$;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3296
|
+ echo ' # With php5-cgi alone:' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3297
|
+ echo ' # fastcgi_pass 127.0.0.1:9000;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3298
|
+ echo ' # With php5-fpm:' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3264
|
3299
|
echo ' fastcgi_pass unix:/var/run/php5-fpm.sock;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3265
|
|
- echo ' fastcgi_index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3266
|
3300
|
echo ' include fastcgi_params;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3301
|
+ echo ' fastcgi_index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3302
|
+ echo ' fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3303
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3304
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3305
|
+ echo ' # deny access to all dot files' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3306
|
+ echo ' location ~ /\. {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3307
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3308
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3309
|
+ echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3310
|
+ echo ' #deny access to store' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3311
|
+ echo ' location ~ /store {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3312
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3313
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3314
|
+ echo ' location ~ /(data|conf|bin|inc)/ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3315
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3316
|
+ echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3317
|
+ echo ' location ~ /\.ht {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
|
3318
|
+ echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3267
|
3319
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3268
|
3320
|
echo '}' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
3269
|
3321
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|