Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

move security.txt block in nginx-drupal #654

Merged
merged 1 commit into from
Jan 20, 2023
Merged

Conversation

tobybellwood
Copy link
Member

@tobybellwood tobybellwood commented Jan 6, 2023

in #500, support for the drupal security.txt module was added to nginx-drupal. In practice though, a higher level match procluded access to .txt files outside of the sites/*/files folder.

This PR moves the security.txt block ahead of that block to ensure it processes ahead of it, and additionally removes the restriction on the .well-known folder being in the webroot - which enables the UI file download for signing in multilingual sites.
image

Copy link
Contributor

@seanhamlin seanhamlin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

After using the PR image (testlagoon/nginx-drupal:pr-654) locally with a Drupal 9.5 site, I can confirm it works as expected. The main issues encountered were with the Drupal module for some reason requiring a permission to 'view' the security.txt file, even after making it. After solving this, all works as expected (both the security.txt file and the security.txt.sig).

image

@tobybellwood tobybellwood merged commit d03c9b5 into main Jan 20, 2023
@tobybellwood tobybellwood deleted the drupal_securitytxt branch January 20, 2023 00:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants