85 lines
2.9 KiB
Text
85 lines
2.9 KiB
Text
|
|
# nginx in front of Sirius Press.
|
||
|
|
#
|
||
|
|
# Static files are served here; only PHP is proxied. That matters more than
|
||
|
|
# usual for this fork: the wallet library and the login script are plain files,
|
||
|
|
# and routing them through PHP-FPM would put a process on the critical path of
|
||
|
|
# every sign-in for no reason.
|
||
|
|
#
|
||
|
|
# TLS is not configured here. Most people putting this on a VPS already have a
|
||
|
|
# reverse proxy, Caddy, or a Cloudflare tunnel in front; baking half a
|
||
|
|
# certificate story into this file would fight all three. docs/install.md
|
||
|
|
# covers the two common arrangements.
|
||
|
|
|
||
|
|
server {
|
||
|
|
listen 80 default_server;
|
||
|
|
server_name _;
|
||
|
|
|
||
|
|
root /var/www/html;
|
||
|
|
index index.php;
|
||
|
|
|
||
|
|
client_max_body_size 64m;
|
||
|
|
|
||
|
|
# WordPress hands its own version out in a header; there is no reason to
|
||
|
|
# advertise nginx's too.
|
||
|
|
server_tokens off;
|
||
|
|
|
||
|
|
add_header X-Content-Type-Options "nosniff" always;
|
||
|
|
add_header X-Frame-Options "SAMEORIGIN" always;
|
||
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
||
|
|
|
||
|
|
# --- things that should never be reachable -------------------------------
|
||
|
|
|
||
|
|
# wp-config.php holds the database password and SIRIUS_PRESS_KEY, which is
|
||
|
|
# what the stored publishing phrase is encrypted under. A misconfiguration
|
||
|
|
# that serves it as text hands over the site's wallet.
|
||
|
|
location = /wp-config.php { deny all; }
|
||
|
|
location ~* /wp-config.*\.php$ { deny all; }
|
||
|
|
location ~ /\.(?!well-known) { deny all; }
|
||
|
|
location = /xmlrpc.php { deny all; }
|
||
|
|
location ~* /(?:uploads|files)/.*\.php$ { deny all; }
|
||
|
|
location ~* ^/wp-content/.*\.(?:sql|log|bak|swp)$ { deny all; }
|
||
|
|
|
||
|
|
# --- routing -------------------------------------------------------------
|
||
|
|
|
||
|
|
location / {
|
||
|
|
try_files $uri $uri/ /index.php?$args;
|
||
|
|
}
|
||
|
|
|
||
|
|
location ~ \.php$ {
|
||
|
|
try_files $uri =404;
|
||
|
|
include fastcgi_params;
|
||
|
|
fastcgi_pass app:9000;
|
||
|
|
fastcgi_index index.php;
|
||
|
|
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||
|
|
fastcgi_param HTTPS $http_x_forwarded_proto if_not_empty;
|
||
|
|
|
||
|
|
# Signature verification on a BCMath host takes a few hundred
|
||
|
|
# milliseconds, and a full static export batch takes longer. The
|
||
|
|
# default 60s would turn a slow first login into a 504.
|
||
|
|
fastcgi_read_timeout 300;
|
||
|
|
fastcgi_buffers 16 16k;
|
||
|
|
fastcgi_buffer_size 32k;
|
||
|
|
}
|
||
|
|
|
||
|
|
# --- caching -------------------------------------------------------------
|
||
|
|
|
||
|
|
location ~* \.(?:css|js|mjs|woff2?|ttf|otf|eot|svg|png|jpe?g|gif|webp|avif|ico)$ {
|
||
|
|
expires 30d;
|
||
|
|
access_log off;
|
||
|
|
add_header Cache-Control "public, max-age=2592000";
|
||
|
|
try_files $uri =404;
|
||
|
|
}
|
||
|
|
|
||
|
|
# The login screen must never be cached anywhere: the challenge it carries
|
||
|
|
# is single-use, and a cached copy would hand every visitor a nonce that
|
||
|
|
# has already been spent.
|
||
|
|
location = /wp-login.php {
|
||
|
|
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
||
|
|
include fastcgi_params;
|
||
|
|
fastcgi_pass app:9000;
|
||
|
|
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
|
||
|
|
fastcgi_param HTTPS $http_x_forwarded_proto if_not_empty;
|
||
|
|
fastcgi_read_timeout 300;
|
||
|
|
}
|
||
|
|
}
|