diff options
context:
space:
mode:
Diffstat (limited to 'custom/servers/lighttpd.conf')
-rw-r--r--custom/servers/lighttpd.conf60
1 file changed, 38 insertions, 22 deletions
diff --git a/custom/servers/lighttpd.conf b/custom/servers/lighttpd.conf
index 3111ed0..6ae87e0 100644
--- a/custom/servers/lighttpd.conf
+++ b/custom/servers/lighttpd.conf
@@ -1,5 +1,11 @@
# lighttpd configuration for cgit.
#
+# This is a complete lighttpd.conf rather than a snippet for conf-enabled, so
+# nothing here is included from elsewhere and no distro base config is
+# assumed. Check it and run it with
+# lighttpd -tt -f /path/to/lighttpd.conf # check the syntax and modules
+# lighttpd -D -f /path/to/lighttpd.conf # run it in the foreground
+#
# lighttpd runs the cgit.cgi binary directly through mod_cgi, so no FastCGI
# bridge is needed. This is cgit's classic reference deployment, mod_cgi with
# mod_alias and mod_setenv.
@@ -16,29 +22,40 @@
# straight off disk and must never be routed through cgit.
-# --- Modules ----------------------------------------------------------------
-# Append the three modules cgit needs so the distro's base config is kept.
-# mod_alias maps URL paths onto files, mod_setenv injects CGIT_CONFIG, and
-# mod_cgi runs cgit.cgi.
-server.modules += ( "mod_alias", "mod_setenv", "mod_cgi" )
+# A plain assignment rather than "+=", since this config stands on its own and
+# there is no distro base list to append to. mod_alias maps URL paths onto
+# files, mod_setenv injects CGIT_CONFIG and the response headers, and mod_cgi
+# runs cgit.cgi. Adding mod_accesslog here is what the access log below needs.
+server.modules = (
+ "mod_alias",
+ "mod_setenv",
+ "mod_cgi",
+ "mod_accesslog",
+)
-# --- Server basics ----------------------------------------------------------
server.port = 80
server.username = "http" # Debian and Ubuntu use www-data
server.groupname = "http"
server.document-root = "/usr/share/cgit" # a valid docroot must exist, the
# alias rules below do the routing
+server.pid-file = "/run/lighttpd.pid"
server.errorlog = "/var/log/lighttpd/error.log"
-# Access logging needs mod_accesslog. Load it and uncomment to enable.
-#server.modules += ( "mod_accesslog" )
-#accesslog.filename = "/var/log/lighttpd/access.log"
+accesslog.filename = "/var/log/lighttpd/access.log"
+
+# Drop the version number from the Server header and from error pages.
+server.tag = "lighttpd"
+
+# The only request body cgit ever reads is the auth-filter login form, and it
+# stops after 4096 bytes. Nothing else here accepts an upload. The value is in
+# kilobytes and the default of 0 means unlimited.
+server.max-request-size = 64
-# --- MIME types for the static assets ---------------------------------------
# mod_alias serves the assets off disk, so lighttpd must know their content
# types. Without this the stylesheet is sent as application/octet-stream and
-# the browser ignores it.
+# the browser ignores it. Only these five files are served off disk, so this
+# short table is the whole of it and no external mime file is needed.
mimetype.assign = (
".css" => "text/css",
".js" => "text/javascript",
@@ -48,20 +65,19 @@ mimetype.assign = (
)
-# --- Virtual host, git.example.org ------------------------------------------
-# A top-level conditional, so it matches on both the port 80 socket and the
-# optional TLS socket at the end of this file.
+# The vhost, as a top-level conditional so it matches on both the port 80
+# socket and the optional TLS socket at the end of this file.
$HTTP["host"] == "git.example.org" {
# Which config cgit reads. It falls back to the compiled-in /etc/cgitrc,
# the same path used here, but setting it makes the location explicit.
setenv.add-environment = ( "CGIT_CONFIG" => "/etc/cgitrc" )
- # --- Security headers ---------------------------------------------------
- # Set here, not in cgit, so they also cover the static assets lighttpd
- # serves. script-src stays self because cgit loads only its own cgit.js,
- # and style-src allows inline for the diffstat bars. If you enable the
- # gravatar or libravatar avatar filter, add its host to img-src.
+ # Security headers are set here, not in cgit, so they also cover the
+ # static assets lighttpd serves. script-src stays self because cgit loads
+ # only its own cgit.js, and style-src allows inline for the diffstat bars.
+ # If you enable the gravatar or libravatar avatar filter, add its host to
+ # img-src.
setenv.add-response-header = (
"Content-Security-Policy" => "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; object-src 'none'; base-uri 'none'; frame-ancestors 'self'",
"X-Content-Type-Options" => "nosniff",
@@ -109,9 +125,9 @@ $HTTP["host"] == "git.example.org" {
}
-# --- Optional HTTPS on 443 --------------------------------------------------
-# Uncomment this whole block to enable TLS. The host block above is socket
-# independent, so it serves cgit over this socket too once the crypto is set.
+# Uncomment this whole block to enable TLS on 443. The host block above is
+# socket independent, so it serves cgit over this socket too once the crypto
+# is set.
#server.modules += ( "mod_openssl" )
#
#$SERVER["socket"] == ":443" {