c
This commit is contained in:
@@ -0,0 +1,91 @@
|
||||
# Redirect all HTTP traffic to HTTPS (forces secure connections)
|
||||
server {
|
||||
listen 80;
|
||||
server_name www.thereisnospoonadu.com thereisnospoonadu.com;
|
||||
|
||||
# Certbot ACME challenge - must be served over HTTP for Let's Encrypt validation
|
||||
location /.well-known/acme-challenge/ {
|
||||
root /var/www/certbot;
|
||||
allow all;
|
||||
}
|
||||
|
||||
location / {
|
||||
return 301 https://$host$request_uri;
|
||||
}
|
||||
}
|
||||
|
||||
# Custom log format: $remote_user is populated by auth_basic, captures real username
|
||||
log_format download '$remote_addr - $remote_user [$time_local] "$request" '
|
||||
'$status $body_bytes_sent "$http_referer" "$http_user_agent"';
|
||||
|
||||
# HTTPS Server Configuration (core SSL setup + Basic Auth download portal)
|
||||
server {
|
||||
listen 443 ssl;
|
||||
server_name www.thereisnospoonadu.com thereisnospoonadu.com;
|
||||
|
||||
# Path to your Certbot SSL certificate (unchanged—valid path)
|
||||
ssl_certificate /etc/letsencrypt/live/www.thereisnospoonadu.com/fullchain.pem;
|
||||
ssl_certificate_key /etc/letsencrypt/live/www.thereisnospoonadu.com/privkey.pem;
|
||||
|
||||
# Modern SSL security settings (A+ grade)
|
||||
ssl_protocols TLSv1.2 TLSv1.3;
|
||||
ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384;
|
||||
ssl_prefer_server_ciphers on;
|
||||
ssl_session_cache shared:SSL:10m;
|
||||
ssl_session_timeout 10m;
|
||||
|
||||
root /www/wwwroot/soft_download;
|
||||
index index.html index.htm;
|
||||
charset utf-8;
|
||||
|
||||
# Entry points: no auth required
|
||||
location = / {
|
||||
try_files /index.html =404;
|
||||
add_header Access-Control-Allow-Origin *;
|
||||
}
|
||||
location = /index.html {
|
||||
add_header Access-Control-Allow-Origin *;
|
||||
}
|
||||
location = /login.html {
|
||||
add_header Access-Control-Allow-Origin *;
|
||||
}
|
||||
|
||||
# API validation endpoint: HTTP Basic Auth
|
||||
location = /api/validate {
|
||||
auth_basic "App Download Portal";
|
||||
auth_basic_user_file /etc/tengine/.htpasswd;
|
||||
default_type text/plain;
|
||||
alias /www/wwwroot/soft_download/api/validate.txt;
|
||||
}
|
||||
|
||||
# JSON file listing: HTTP Basic Auth
|
||||
location /list/ {
|
||||
auth_basic "App Download Portal";
|
||||
auth_basic_user_file /etc/tengine/.htpasswd;
|
||||
alias /www/wwwroot/soft_download/;
|
||||
index nothing_will_match;
|
||||
autoindex on;
|
||||
autoindex_exact_size off;
|
||||
autoindex_localtime on;
|
||||
autoindex_format json;
|
||||
add_header Access-Control-Allow-Origin *;
|
||||
}
|
||||
|
||||
# File downloads: no auth required (username tracked via ?u= query param)
|
||||
location ~ \.(exe|md|pdf|zip|rar|7z|tar|gz|txt|doc|docx|xls|xlsx|ppt|pptx|deb)$ {
|
||||
add_header Access-Control-Allow-Origin *;
|
||||
}
|
||||
|
||||
# All other paths: serve static files (no auth)
|
||||
location / {
|
||||
try_files $uri $uri/ =404;
|
||||
error_page 403 = /index.html;
|
||||
add_header Access-Control-Allow-Origin *;
|
||||
}
|
||||
|
||||
access_log /usr/local/nginx/logs/download_access.log download;
|
||||
error_log /usr/local/nginx/logs/download_error.log warn;
|
||||
|
||||
# Security: Hide Nginx version
|
||||
server_tokens off;
|
||||
}
|
||||
Reference in New Issue
Block a user