Skip to content
Snippets Groups Projects
Unverified Commit dea781af authored by nl6720's avatar nl6720
Browse files

archweb: use a whitelist for files in /iso/

Allow only .sig, .torrent and .txt.

This is done to prevent downloading files such as https://archlinux.org/iso/latest/arch/boot/x86_64/vmlinuz-linux.
parent fe1d9d4c
No related branches found
No related tags found
1 merge request!595archweb: use a whitelist for files in /iso/
......@@ -151,12 +151,14 @@ server {
alias {{ archweb_dir }}/archlinux.org/logos/;
}
location ~ ^/iso/(.*\.(iso|img|tar\.gz|sfs)$) {
deny all;
}
location /iso/ {
alias {{ archweb_rsync_iso_dir }};
location ~ ^/iso/.*\.(sig|torrent|txt)$ {
}
location /iso/ {
deny all;
}
}
# Cache django's css, js and png files.
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment