Adds integration tests for per path access lists, fixes ipv6 jsv,

and enforces host-wide access list when location access list is not set
This commit is contained in:
Jamie Curnow
2026-09-24 12:21:49 +10:00
parent c41ec008bb
commit 2cfd3395cf
21 changed files with 518 additions and 103 deletions
+29
View File
@@ -0,0 +1,29 @@
server {
listen 80;
server_name website1.example.com website2.example.com website3.example.com;
root /www;
index index.html;
# redirect requests for .html URLs to their extensionless form
if ($request_uri ~ ^/index\.html(\?.*)?$) {
return 301 /$1;
}
if ($request_uri ~ ^/(.+)\.html(\?.*)?$) {
return 301 /$1$2;
}
location / {
try_files $uri $uri.html $uri/ =404;
}
error_page 404 /404.html;
location = /404.html {
internal;
}
# deny access to .htaccess files, if Apache's document root
# concurs with nginx's one
location ~ /\.ht {
deny all;
}
}
+30
View File
@@ -0,0 +1,30 @@
user nginx;
worker_processes auto;
error_log /var/log/nginx/error.log notice;
pid /run/nginx.pid;
events {
worker_connections 1024;
}
http {
include /etc/nginx/mime.types;
default_type application/octet-stream;
server_tokens off;
log_format custom_combined '$remote_addr - $remote_user [$time_local] "$host" "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent"';
access_log /var/log/nginx/access.log custom_combined;
sendfile on;
tcp_nopush on;
keepalive_timeout 65;
gzip on;
set_real_ip_from 10.0.0.0/8;
set_real_ip_from 172.16.0.0/12; # Includes Docker subnet
set_real_ip_from 192.168.0.0/16;
include include/*.conf;
include conf.d/*.conf;
include /sites/*/nginx.conf;
}