X-Git-Url: https://git.mxchange.org/?a=blobdiff_plain;f=mods%2Fsample-nginx.config;h=5530bfaefd9cff6d328c81518df30da9bfe8c017;hb=539ac4f2b82e661d63b17c5276550ba6120806fe;hp=0b96f50ba795b0b1f3253e9d662a2076b9dd7c6e;hpb=92f47f8ecae754448431110110a20acf3a80120f;p=friendica.git diff --git a/mods/sample-nginx.config b/mods/sample-nginx.config index 0b96f50ba7..5530bfaefd 100644 --- a/mods/sample-nginx.config +++ b/mods/sample-nginx.config @@ -35,7 +35,7 @@ server { index index.php; root /var/www/friendica; - rewrite ^ https://friendica.example.net$request_uri? permanent; + rewrite ^ https://$server_name$request_uri? permanent; } ## @@ -51,8 +51,6 @@ server { listen 443 ssl; server_name friendica.example.net; - ssl on; - #Traditional SSL ssl_certificate /etc/nginx/ssl/friendica.example.net.chain.pem; ssl_certificate_key /etc/nginx/ssl/example.net.key; @@ -84,26 +82,25 @@ server { # rewrite to front controller as default rule location / { - if (!-e $request_filename) { - rewrite ^(.*)$ /index.php?pagename=$1; - } + try_files $uri /index.php?pagename=$uri&$args; } # make sure webfinger and other well known services aren't blocked # by denying dot files and rewrite request to the front controller location ^~ /.well-known/ { allow all; - if (!-e $request_filename) { - rewrite ^(.*)$ /index.php?pagename=$1; - } + rewrite ^ /index.php?pagename=$uri; } include mime.types; - # block these file types - location ~* \.(tpl|md|tgz|log|out)$ { - deny all; - } + # statically serve these file types when possible otherwise fall back to + # front controller allow browser to cache them added .htm for advanced source + # code editor library + #location ~* \.(jpg|jpeg|gif|png|ico|css|js|htm|html|ttf|woff|svg)$ { + # expires 30d; + # try_files $uri /index.php?pagename=$uri&$args; + #} # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 # or a unix socket @@ -123,15 +120,28 @@ server { # fastcgi_pass 127.0.0.1:9000; # With php7.0-fpm: - fastcgi_pass unix:/var/run/php/php7.0-fpm.sock; + fastcgi_pass unix:/var/run/php/php7.4-fpm.sock; include fastcgi_params; fastcgi_index index.php; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; + + fastcgi_buffers 16 16k; + fastcgi_buffer_size 32k; + } + + # block these file types + location ~* \.(tpl|md|tgz|log|out)$ { + deny all; } # deny access to all dot files location ~ /\. { deny all; } + + # deny access to the CLI scripts + location ^~ /bin { + deny all; + } }