|
|
@@ -1,3 +1,8 @@
|
|
|
+{% include "_assets.conf" %}
|
|
|
+{% include "_exploits.conf" %}
|
|
|
+{% include "_hsts.conf" %}
|
|
|
+
|
|
|
+
|
|
|
location {{ path }} {
|
|
|
proxy_set_header Host $host;
|
|
|
proxy_set_header X-Forwarded-Scheme $scheme;
|
|
|
@@ -6,25 +11,26 @@
|
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
|
proxy_pass {{ forward_scheme }}://{{ forward_host }}:{{ forward_port }}{{ forward_path }};
|
|
|
|
|
|
+
|
|
|
{% if access_list_id > 0 %}
|
|
|
{% if access_list.items.length > 0 %}
|
|
|
# Authorization
|
|
|
auth_basic "Authorization required";
|
|
|
auth_basic_user_file /data/access/{{ access_list_id }};
|
|
|
-
|
|
|
+
|
|
|
{{ access_list.passauth }}
|
|
|
{% endif %}
|
|
|
-
|
|
|
+
|
|
|
# Access Rules
|
|
|
{% for client in access_list.clients %}
|
|
|
{{- client.rule -}};
|
|
|
{% endfor %}deny all;
|
|
|
-
|
|
|
+
|
|
|
# Access checks must...
|
|
|
{% if access_list.satisfy %}
|
|
|
{{ access_list.satisfy }};
|
|
|
{% endif %}
|
|
|
-
|
|
|
+
|
|
|
{% endif %}
|
|
|
|
|
|
|