Skip to content

feat: include nginx server snippets from server.d - #38

Open
YvesCesar wants to merge 2 commits into
mainfrom
feat/nginx-server-snippets
Open

YvesCesar wants to merge 2 commits into
mainfrom
feat/nginx-server-snippets

Conversation

@YvesCesar

Copy link
Copy Markdown
Member

Projects built on this stack currently replace the whole default.conf to change a single directive (e.g. client_max_body_size in LibreSign/saas). That copy drifts from upstream and silently drops hardening added here, such as the XML-RPC include and the uploads/ PHP rule.

This includes every *.conf mounted at /etc/nginx/server.d/ at the end of the server block, so an environment can tune nginx without copying the config. The include is placed after all locations, so a snippet cannot take precedence over the existing deny rules. With nothing mounted, the glob matches no file and nginx starts normally.

The README documents the mount with a client_max_body_size example.

Tests

tests/security/nginx-server-snippets.bats runs the real default.conf against PHP-FPM:

  • without snippets the config is valid and a 2 KiB POST reaches PHP;
  • with a client_max_body_size 1k; snippet the same POST gets 413 before PHP.

Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Signed-off-by: YvesCesar <yvesamorim73@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant