1
0
mirror of https://github.com/go-gitea/gitea synced 2024-12-24 03:35:55 +01:00

Fix alias traversal (#20076)

see https://github.com/yandex/gixy/blob/master/docs/en/plugins/aliastraversal.md

Co-authored-by: 6543 <6543@obermui.de>
This commit is contained in:
Sandro 2022-06-22 10:15:49 +02:00 committed by GitHub
parent 031f5f7b7c
commit e9aa698cf0
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

@ -88,8 +88,8 @@ server {
listen 80;
server_name git.example.com;
location /_/static/assets {
alias /path/to/gitea/public;
location /_/static/assets/ {
alias /path/to/gitea/public/;
}
location / {
@ -120,8 +120,8 @@ server {
listen 80;
server_name cdn.example.com;
location /gitea {
alias /path/to/gitea/public;
location /gitea/ {
alias /path/to/gitea/public/;
}
location / {
@ -362,4 +362,4 @@ gitea:
- "traefik.http.services.gitea-websecure.loadbalancer.server.port=3000"
```
This config assumes that you are handling HTTPS on the traefik side and using HTTP between Gitea and traefik.
This config assumes that you are handling HTTPS on the traefik side and using HTTP between Gitea and traefik.