Skip to content

Commit

Permalink
chore: check if the directory is known by lagoon nginx when it's part…
Browse files Browse the repository at this point in the history
… of the repo
  • Loading branch information
colorfield committed Oct 18, 2023
1 parent ecdbfcd commit 0f47627
Show file tree
Hide file tree
Showing 3 changed files with 35 additions and 1 deletion.
2 changes: 1 addition & 1 deletion apps/cms/.gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -30,4 +30,4 @@ generated/operations.json
generated/translations.json

# OAuth2
/keys
#/keys
27 changes: 27 additions & 0 deletions apps/cms/keys/.htaccess
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
# Deny all requests from Apache 2.4+.
<IfModule mod_authz_core.c>
Require all denied
</IfModule>

# Deny all requests from Apache 2.0-2.2.
<IfModule !mod_authz_core.c>
Deny from all
</IfModule>

# Turn off all options we don't need.
Options -Indexes -ExecCGI -Includes -MultiViews

# Set the catch-all handler to prevent scripts from being executed.
SetHandler Drupal_Security_Do_Not_Remove_See_SA_2006_006
<Files *>
# Override the handler again if we're run later in the evaluation list.
SetHandler Drupal_Security_Do_Not_Remove_See_SA_2013_003
</Files>

# If we know how to do it safely, disable the PHP engine entirely.
<IfModule mod_php7.c>
php_flag engine off
</IfModule>
<IfModule mod_php.c>
php_flag engine off
</IfModule>
7 changes: 7 additions & 0 deletions apps/cms/keys/web.config
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
<configuration>
<system.webServer>
<authorization>
<deny users="*">
</authorization>
</system.webServer>
</configuration>

0 comments on commit 0f47627

Please sign in to comment.