mirror of
https://github.com/certbot/certbot.git
synced 2026-07-27 00:00:44 +02:00
Another token of gratitude for a super useful tool and service. More about codespell: https://github.com/codespell-project/codespell . I personally introduced it to dozens if not hundreds of projects already and so far only positive feedback. CI workflow has 'permissions' set only to 'read' so also should be safe. --------- Signed-off-by: Yaroslav O. Halchenko <debian@onerussian.com>
71 lines
2.0 KiB
Nginx Configuration File
71 lines
2.0 KiB
Nginx Configuration File
server {
|
|
## This is to avoid the spurious if for sub-domain name rewriting.
|
|
listen [::]:80;
|
|
server_name www.stats.example.com;
|
|
rewrite ^ $scheme://stats.example.com$request_uri? permanent;
|
|
}
|
|
|
|
server {
|
|
listen [::]:80;
|
|
limit_conn arbeit 10;
|
|
server_name stats.example.com;
|
|
|
|
# Parameterization using hostname of access and log filenames.
|
|
access_log /var/log/nginx/stats.example.com_access.log;
|
|
error_log /var/log/nginx/stats.example.com_error.log;
|
|
|
|
# Disable all methods besides HEAD, GET and POST.
|
|
if ($request_method !~ ^(GET|HEAD|POST)$ ) {
|
|
return 444;
|
|
}
|
|
|
|
root /var/www/sites/stats.example.com/;
|
|
index index.php index.html;
|
|
|
|
# Disallow any usage of piwik assets if referer is non valid.
|
|
location ~* ^.+\.(?:jpg|png|css|gif|jpeg|js|swf)$ {
|
|
# Defining the valid referrers.
|
|
valid_referers none blocked *.mysite.com othersite.com;
|
|
if ($invalid_referer) {
|
|
return 444;
|
|
}
|
|
expires max;
|
|
break;
|
|
}
|
|
|
|
# Support for favicon. Return a 204 (No Content) if the favicon
|
|
# doesn't exist.
|
|
location = /favicon.ico {
|
|
try_files /favicon.ico =204;
|
|
}
|
|
|
|
# Try all locations and relay to index.php as a fallback.
|
|
location / {
|
|
try_files $uri /index.php;
|
|
}
|
|
|
|
# Relay all index.php requests to fastcgi.
|
|
location ~* ^/(?:index|piwik)\.php$ {
|
|
fastcgi_pass unix:/tmp/php-cgi/php-cgi.socket;
|
|
}
|
|
|
|
# Any other attempt to access PHP files returns a 404.
|
|
location ~* ^.+\.php$ {
|
|
return 404;
|
|
}
|
|
|
|
# Return a 404 for all text files.
|
|
location ~* ^/(?:README|LICENSE[^.]*|LEGALNOTICE)(?:\.txt)*$ {
|
|
return 404;
|
|
}
|
|
|
|
# # The 404 is signaled through a static page.
|
|
# error_page 404 /404.html;
|
|
|
|
# ## All server error pages go to 50x.html at the document root.
|
|
# error_page 500 502 503 504 /50x.html;
|
|
# location = /50x.html {
|
|
# root /var/www/nginx-default;
|
|
# }
|
|
} # server
|