36 lines
1.3 KiB
Plaintext
36 lines
1.3 KiB
Plaintext
# block direct access to templates, XML schemas, config files, dotfiles, environment info, etc.
|
|
location ~ ^/board/modules/editor/(skins|styles)/.+\.html$ {
|
|
# pass
|
|
}
|
|
location ~ ^/board/(addons|common/tpl|files/ruleset|(m\.)?layouts|modules|plugins|themes|widgets|widgetstyles)/.+\.(html|xml)$ {
|
|
return 403;
|
|
}
|
|
location ~ ^/board/files/(attach|config|cache/store)/.+\.(ph(p|t|ar)?[0-9]?|p?html?|cgi|pl|exe|[aj]spx?|inc|bak)$ {
|
|
return 403;
|
|
}
|
|
location ~ ^/board/files/(env|member_extra_info/(new_message_flags|point))/ {
|
|
return 403;
|
|
}
|
|
location ~ ^/board/(\.git|\.ht|\.travis|codeception\.|composer\.|Gruntfile\.js|package\.json|CONTRIBUTING|COPYRIGHT|LICENSE|README) {
|
|
return 403;
|
|
}
|
|
|
|
# fix incorrect relative URLs (for legacy support)
|
|
location ~ ^/board/(.+)/(addons|files|layouts|m\.layouts|modules|widgets|widgetstyles)/(.+) {
|
|
try_files $uri $uri/ /board/$2/$3;
|
|
}
|
|
|
|
# fix incorrect minified URLs (for legacy support)
|
|
location ~ ^/board/(.+)\.min\.(css|js)$ {
|
|
try_files $uri $uri/ /board/$1.$2;
|
|
}
|
|
|
|
# fix download URL when other directives for static files are present
|
|
location ~ ^/board/files/download/ {
|
|
try_files $uri $uri/ /board/index.php$is_args$args;
|
|
}
|
|
|
|
# all other short URLs
|
|
location /board/ {
|
|
try_files $uri $uri/ /board/index.php$is_args$args;
|
|
} |