Browse Source

cryptpad settings

Bob Mottram 8 years ago
parent
commit
b7e0e548b7
1 changed files with 27 additions and 6 deletions
  1. 27
    6
      src/freedombone-app-cryptpad

+ 27
- 6
src/freedombone-app-cryptpad View File

330
 
330
 
331
         echo '  add_header Strict-Transport-Security max-age=15768000;' >> $cryptpad_nginx_site
331
         echo '  add_header Strict-Transport-Security max-age=15768000;' >> $cryptpad_nginx_site
332
         echo '' >> $cryptpad_nginx_site
332
         echo '' >> $cryptpad_nginx_site
333
+        echo '  if ($uri = /pad/inner.html) {' >> $cryptpad_nginx_site
334
+        echo "    set \$scriptSrc \"'self' 'unsafe-eval' 'unsafe-inline'\";" >> $cryptpad_nginx_site
335
+        echo '  }' >> $cryptpad_nginx_site
336
+        echo '' >> $cryptpad_nginx_site
333
         echo '  # Logs' >> $cryptpad_nginx_site
337
         echo '  # Logs' >> $cryptpad_nginx_site
334
         echo '  access_log /dev/null;' >> $cryptpad_nginx_site
338
         echo '  access_log /dev/null;' >> $cryptpad_nginx_site
335
         echo '  error_log /dev/null;' >> $cryptpad_nginx_site
339
         echo '  error_log /dev/null;' >> $cryptpad_nginx_site
372
         echo '    rewrite ^(.*)$ $1/ redirect;' >> $cryptpad_nginx_site
376
         echo '    rewrite ^(.*)$ $1/ redirect;' >> $cryptpad_nginx_site
373
         echo '  }' >> $cryptpad_nginx_site
377
         echo '  }' >> $cryptpad_nginx_site
374
         echo '' >> $cryptpad_nginx_site
378
         echo '' >> $cryptpad_nginx_site
375
-        echo '  try_files $uri $uri/index.html /customize/$uri;' >> $cryptpad_nginx_site
379
+        echo '  try_files /www/$uri /www/$uri/index.html /customize/$uri;' >> $cryptpad_nginx_site
376
         echo '}' >> $cryptpad_nginx_site
380
         echo '}' >> $cryptpad_nginx_site
377
     else
381
     else
378
         echo -n '' > $cryptpad_nginx_site
382
         echo -n '' > $cryptpad_nginx_site
379
     fi
383
     fi
380
     echo 'server {' >> $cryptpad_nginx_site
384
     echo 'server {' >> $cryptpad_nginx_site
381
-    echo "    listen 127.0.0.1:$CRYPTPAD_ONION_PORT default_server;" >> $cryptpad_nginx_site
382
-    echo "    server_name $CRYPTPAD_ONION_HOSTNAME;" >> $cryptpad_nginx_site
385
+    echo "  listen 127.0.0.1:$CRYPTPAD_ONION_PORT default_server;" >> $cryptpad_nginx_site
386
+    echo "  server_name $CRYPTPAD_ONION_HOSTNAME;" >> $cryptpad_nginx_site
383
     echo '' >> $cryptpad_nginx_site
387
     echo '' >> $cryptpad_nginx_site
384
     echo '  # Logs' >> $cryptpad_nginx_site
388
     echo '  # Logs' >> $cryptpad_nginx_site
385
     echo '  access_log /dev/null;' >> $cryptpad_nginx_site
389
     echo '  access_log /dev/null;' >> $cryptpad_nginx_site
390
     echo '' >> $cryptpad_nginx_site
394
     echo '' >> $cryptpad_nginx_site
391
     echo '  index index.html;' >> $cryptpad_nginx_site
395
     echo '  index index.html;' >> $cryptpad_nginx_site
392
     echo '' >> $cryptpad_nginx_site
396
     echo '' >> $cryptpad_nginx_site
397
+    echo '  add_header X-XSS-Protection "1; mode=block";' >> $cryptpad_nginx_site
398
+    echo '  add_header X-Content-Type-Options nosniff;' >> $cryptpad_nginx_site
399
+    echo '  add_header X-Frame-Options SAMEORIGIN;' >> $cryptpad_nginx_site
400
+    echo '' >> $cryptpad_nginx_site
401
+    echo '  if ($uri = /pad/inner.html) {' >> $cryptpad_nginx_site
402
+    echo "    set \$scriptSrc \"'self' 'unsafe-eval' 'unsafe-inline'\";" >> $cryptpad_nginx_site
403
+    echo '  }' >> $cryptpad_nginx_site
404
+    echo '' >> $cryptpad_nginx_site
405
+    echo "  add_header Content-Security-Policy \"default-src http:; script-src http: 'unsafe-inline'; style-src http: 'unsafe-inline'; img-src data: * blob: font-src self\";" >> $cryptpad_nginx_site
406
+    echo '' >> $cryptpad_nginx_site
393
     echo '  location = /cryptpad_websocket {' >> $cryptpad_nginx_site
407
     echo '  location = /cryptpad_websocket {' >> $cryptpad_nginx_site
394
     echo "    proxy_pass http://localhost:$CRYPTPAD_PORT;" >> $cryptpad_nginx_site
408
     echo "    proxy_pass http://localhost:$CRYPTPAD_PORT;" >> $cryptpad_nginx_site
395
     echo '    proxy_set_header X-Real-IP $remote_addr;' >> $cryptpad_nginx_site
409
     echo '    proxy_set_header X-Real-IP $remote_addr;' >> $cryptpad_nginx_site
423
     echo '    rewrite ^(.*)$ $1/ redirect;' >> $cryptpad_nginx_site
437
     echo '    rewrite ^(.*)$ $1/ redirect;' >> $cryptpad_nginx_site
424
     echo '  }' >> $cryptpad_nginx_site
438
     echo '  }' >> $cryptpad_nginx_site
425
     echo '' >> $cryptpad_nginx_site
439
     echo '' >> $cryptpad_nginx_site
426
-    echo '  try_files $uri $uri/index.html /customize/$uri;' >> $cryptpad_nginx_site
440
+    echo '  try_files /www/$uri /www/$uri/index.html /customize/$uri;' >> $cryptpad_nginx_site
427
     echo '}' >> $cryptpad_nginx_site
441
     echo '}' >> $cryptpad_nginx_site
428
 
442
 
429
     sed -i 's|DENY;|SAMEORIGIN;|g' $cryptpad_nginx_site
443
     sed -i 's|DENY;|SAMEORIGIN;|g' $cryptpad_nginx_site
444
+    sed -i "s|Content-Security-Policy.*|Content-Security-Policy \"default-src http:; script-src http: 'unsafe-inline'; style-src http: 'unsafe-inline'; img-src data: * blob: font-src self\";|g" $cryptpad_nginx_site
430
 
445
 
431
     function_check create_site_certificate
446
     function_check create_site_certificate
432
     create_site_certificate $CRYPTPAD_DOMAIN_NAME 'yes'
447
     create_site_certificate $CRYPTPAD_DOMAIN_NAME 'yes'
463
     fi
478
     fi
464
 
479
 
465
     sed -i "s|httpPort:.*|httpPort: $CRYPTPAD_PORT,|g" config.js
480
     sed -i "s|httpPort:.*|httpPort: $CRYPTPAD_PORT,|g" config.js
466
-    sed -i "s|websocketPath:.*|websocketPath: '/',|g" config.js
467
     sed -i "s|// domain:|domain:|g" config.js
481
     sed -i "s|// domain:|domain:|g" config.js
468
     sed -i 's|openFileLimit:.*|openFileLimit: 1024,|g' config.js
482
     sed -i 's|openFileLimit:.*|openFileLimit: 1024,|g' config.js
469
     if [[ $ONION_ONLY == 'no' ]]; then
483
     if [[ $ONION_ONLY == 'no' ]]; then
471
     else
485
     else
472
         sed -i "s|domain:.*|domain: 'http://$CRYPTPAD_ONION_HOSTNAME',|g" config.js
486
         sed -i "s|domain:.*|domain: 'http://$CRYPTPAD_ONION_HOSTNAME',|g" config.js
473
     fi
487
     fi
488
+    #if [[ $ONION_ONLY != 'no' ]]; then
489
+    #    sed -i "/module.exports/a ]," config.js
490
+    #    sed -i "/module.exports/a '\/etc\/ssl\/private\/${CRYPTPAD_DOMAIN_NAME}.key'" config.js
491
+    #    sed -i "/module.exports/a '\/etc\/ssl\/certs\/${CRYPTPAD_DOMAIN_NAME}.pem'" config.js
492
+    #    sed -i "/module.exports/a privKeyAndCertFiles: [" config.js
493
+    #fi
474
 
494
 
475
     chown -R cryptpad:cryptpad $CRYPTPAD_DIR
495
     chown -R cryptpad:cryptpad $CRYPTPAD_DIR
476
 
496
 
481
     echo 'After=network.target' >> /etc/systemd/system/cryptpad.service
501
     echo 'After=network.target' >> /etc/systemd/system/cryptpad.service
482
     echo '' >> /etc/systemd/system/cryptpad.service
502
     echo '' >> /etc/systemd/system/cryptpad.service
483
     echo '[Service]' >> /etc/systemd/system/cryptpad.service
503
     echo '[Service]' >> /etc/systemd/system/cryptpad.service
484
-    echo 'Type=simple' >> /etc/systemd/system/cryptpad.service
485
     echo 'User=cryptpad' >> /etc/systemd/system/cryptpad.service
504
     echo 'User=cryptpad' >> /etc/systemd/system/cryptpad.service
486
     echo 'Group=cryptpad' >> /etc/systemd/system/cryptpad.service
505
     echo 'Group=cryptpad' >> /etc/systemd/system/cryptpad.service
487
     echo "WorkingDirectory=$CRYPTPAD_DIR" >> /etc/systemd/system/cryptpad.service
506
     echo "WorkingDirectory=$CRYPTPAD_DIR" >> /etc/systemd/system/cryptpad.service
488
     echo "ExecStart=/usr/local/bin/node $CRYPTPAD_DIR/server.js" >> /etc/systemd/system/cryptpad.service
507
     echo "ExecStart=/usr/local/bin/node $CRYPTPAD_DIR/server.js" >> /etc/systemd/system/cryptpad.service
508
+    echo 'Environment=PATH=/usr/bin:/usr/local/bin' >> /etc/systemd/system/cryptpad.service
509
+    echo 'Environment=NODE_ENV=production' >> /etc/systemd/system/cryptpad.service
489
     echo 'Restart=on-failure' >> /etc/systemd/system/cryptpad.service
510
     echo 'Restart=on-failure' >> /etc/systemd/system/cryptpad.service
490
     echo '' >> /etc/systemd/system/cryptpad.service
511
     echo '' >> /etc/systemd/system/cryptpad.service
491
     echo '[Install]' >> /etc/systemd/system/cryptpad.service
512
     echo '[Install]' >> /etc/systemd/system/cryptpad.service