Bladeren bron

Make dokuwiki http and https configurations similar

Bob Mottram 10 jaren geleden
bovenliggende
commit
b0d0fc7b91
1 gewijzigde bestanden met toevoegingen van 59 en 7 verwijderingen
  1. 59
    7
      install-freedombone.sh

+ 59
- 7
install-freedombone.sh Bestand weergeven

@@ -3247,23 +3247,75 @@ function install_wiki {
3247 3247
 
3248 3248
   echo 'server {' > /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3249 3249
   echo '    listen 80;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3250
-  echo "    server_name $WIKI_DOMAIN_NAME;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3251 3250
   echo "    root /var/www/$WIKI_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3251
+  echo "    server_name $WIKI_DOMAIN_NAME;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3252 3252
   echo "    error_log /var/www/$WIKI_DOMAIN_NAME/error.log;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3253 3253
   echo '    index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3254
+  echo '    charset utf-8;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3255
+  echo '    client_max_body_size 20m;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3256
+  echo '    client_body_buffer_size 128k;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3254 3257
   echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3255
-  echo '    # Uncomment this if you need to redirect HTTP to HTTPS' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3256
-  echo '    #rewrite ^ https://$server_name$request_uri? permanent;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3257
-  echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3258
+  echo '    # rewrite to front controller as default rule' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3258 3259
   echo '    location / {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3259
-  echo '        try_files $uri $uri/ /index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3260
+  echo '        rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3261
+  echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3262
+  echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3263
+  echo "    # make sure webfinger and other well known services aren't blocked" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3264
+  echo '    # by denying dot files and rewrite request to the front controller' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3265
+  echo '    location ^~ /.well-known/ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3266
+  echo '        allow all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3267
+  echo '        rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3260 3268
   echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3261 3269
   echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3262
-  echo '    location ~ \.php$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3270
+  echo '    # statically serve these file types when possible' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3271
+  echo '    # otherwise fall back to front controller' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3272
+  echo '    # allow browser to cache them' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3273
+  echo '    # added .htm for advanced source code editor library' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3274
+  echo '    location ~* \.(jpg|jpeg|gif|png|ico|css|js|htm|html|ttf|woff|svg)$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3275
+  echo '        expires 30d;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3276
+  echo '        try_files $uri /index.php?q=$uri&$args;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3277
+  echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3278
+  echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3279
+  echo '    # block these file types' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3280
+  echo '    location ~* \.(tpl|md|tgz|log|out)$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3281
+  echo '        deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3282
+  echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3283
+  echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3284
+  echo '    # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3285
+  echo '    # or a unix socket' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3286
+  echo '    location ~* \.php$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3287
+  echo '        # Zero-day exploit defense.' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3288
+  echo '        # http://forum.nginx.org/read.php?2,88845,page=3' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3289
+  echo "        # Won't work properly (404 error) if the file is not stored on this" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3290
+  echo "        # server, which is entirely possible with php-fpm/php-fcgi." >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3291
+  echo "        # Comment the 'try_files' line out if you set up php-fpm/php-fcgi on" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3292
+  echo "        # another machine. And then cross your fingers that you won't get hacked." >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3293
+  echo '        try_files $uri $uri/ /index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3294
+  echo '        # NOTE: You should have "cgi.fix_pathinfo = 0;" in php.ini' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3263 3295
   echo '        fastcgi_split_path_info ^(.+\.php)(/.+)$;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3296
+  echo '        # With php5-cgi alone:' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3297
+  echo '        # fastcgi_pass 127.0.0.1:9000;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3298
+  echo '        # With php5-fpm:' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3264 3299
   echo '        fastcgi_pass unix:/var/run/php5-fpm.sock;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3265
-  echo '        fastcgi_index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3266 3300
   echo '        include fastcgi_params;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3301
+  echo '        fastcgi_index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3302
+  echo '        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3303
+  echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3304
+  echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3305
+  echo '    # deny access to all dot files' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3306
+  echo '    location ~ /\. {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3307
+  echo '        deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3308
+  echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3309
+  echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3310
+  echo '    #deny access to store' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3311
+  echo '    location ~ /store {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3312
+  echo '        deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3313
+  echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3314
+  echo '    location ~ /(data|conf|bin|inc)/ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3315
+  echo '      deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3316
+  echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3317
+  echo '    location ~ /\.ht {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3318
+  echo '      deny  all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3267 3319
   echo '    }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3268 3320
   echo '}' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
3269 3321
   echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME