diff options
| -rw-r--r-- | custom/servers/nginx.conf | 31 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 31 insertions, 0 deletions
diff --git a/custom/servers/nginx.conf b/custom/servers/nginx.conf index f26598c..cf1e49f 100644 --- a/custom/servers/nginx.conf +++ b/custom/servers/nginx.conf @@ -80,6 +80,37 @@ http { gzip_types text/css text/javascript text/plain application/atom+xml; + # Requests carrying a Host header this config does not serve, a raw IP or + # an invented name from a scanning bot, land in these two blocks and are + # dropped without a response. cgit keys its page cache on the Host header + # so clone URLs stay honest, which means every invented hostname reaching + # it would mint a cache entry of its own and evict a real page to make + # room. Refusing strangers here keeps the cache to the names the site + # actually answers to. 444 is nginx shorthand for closing the connection + # without replying. + server { + listen 80 default_server; + listen [::]:80 default_server; + server_name _; + return 444; + } + + server { + listen 443 ssl default_server; + listen [::]:443 ssl default_server; + server_name _; + # Refuse the TLS handshake itself when the SNI name is unknown, which + # also spares this block from needing a certificate. Requires nginx + # 1.19.4 or newer. On older builds point ssl_certificate at any cert, + # a self-signed one included, and rely on the return below. + ssl_reject_handshake on; + # A client can still handshake against a real name and then send some + # other Host header. Those requests route here after the handshake, + # past the rejection above, so close them too. + return 444; + } + + # Bounce plain HTTP up to HTTPS. Delete this whole server block if you # serve plain HTTP only. server { |
