Update default.conf.sample to deny dotfile access#134
Update default.conf.sample to deny dotfile access#134
Conversation
Signed-off-by: Eric Nemchik <eric@nemchik.com>
|
I am a bot, here is the pushed image/manifest for this PR:
|
|
I am a bot, here is the pushed image/manifest for this PR:
|
|
I am a bot, here is the pushed image/manifest for this PR:
|
|
This pull request has been automatically marked as stale because it has not had recent activity. This might be due to missing feedback from OP. It will be closed if no further activity occurs. Thank you for your contributions. |
Signed-off-by: Eric Nemchik <eric@nemchik.com>
There was a problem hiding this comment.
Pull request overview
Updates the container’s default Nginx site config sample to prevent serving dotfiles (while still allowing /.well-known), and records the change in the generated README changelog.
Changes:
- Add an explicit allow-list for
/.well-knownand a blanket deny for all dotfiles in the default Nginx sample config. - Remove the older
.ht*-specific deny rule since dotfiles are now handled generically. - Update the sample config version header and add a README changelog entry (also adds QUIC listeners on 443).
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.
| File | Description |
|---|---|
| root/defaults/nginx/site-confs/default.conf.sample | Adds /.well-known allow and global dotfile deny; removes legacy .ht* block; also adds QUIC listen directives. |
| readme-vars.yml | Adds a changelog entry instructing existing users to update their Nginx config. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| listen 443 ssl default_server; | ||
| listen [::]:443 ssl default_server; | ||
| listen 443 quic reuseport default_server; | ||
| listen [::]:443 quic reuseport default_server; |
| location ^~ /.well-known { | ||
| allow all; | ||
| } | ||
|
|
| "mastodon:develop" <- Base Images | ||
| # changelog | ||
| changelogs: | ||
| - {date: "08.02.26:", desc: "Existing users should update: site-confs/default.conf - Deny access to all dotfiles."} |
No description provided.