mirror of
https://github.com/netbirdio/plugins.git
synced 2026-05-22 18:44:07 -07:00
www/nginx: hide upstream headers (#983)
* www/nginx: do not pass headers which are added by nginx (duplication issue), fixes #971 * www/nginx: update changelog * www/nginx: forgot this one * more verbose release note
This commit is contained in:
@@ -16,9 +16,11 @@ Plugin Changelog
|
||||
* change: allow to disable internal bot protection (contributed by @fzoske) [2]
|
||||
* change: do not save when no change in the list happened to prevent filling the log history
|
||||
* fix: translate a german string in upstream server to english
|
||||
* replace headers instead of just adding our own (duplication issue #971), suppress X-Powered-By from Upstream [3]
|
||||
|
||||
[1] https://github.com/opnsense/plugins/pull/930
|
||||
[2] https://github.com/opnsense/plugins/pull/934
|
||||
[3] https://github.com/opnsense/plugins/issues/971
|
||||
|
||||
1.3
|
||||
|
||||
|
||||
@@ -57,6 +57,8 @@ if cache_path.use_temp_path is defined and cache_path.use_temp_path == '1'
|
||||
{% for server in helpers.toList('OPNsense.Nginx.http_server') %}
|
||||
{% set single_servername = server.servername.split(",")[0] %}
|
||||
server {
|
||||
{% set our_headers = [] %}
|
||||
{% do our_headers.append('X-Powered-By') %}
|
||||
{% if server.listen_http_port is defined %}
|
||||
listen {{ server.listen_http_port }};
|
||||
listen [::]:{{ server.listen_http_port }};
|
||||
@@ -80,6 +82,7 @@ server {
|
||||
ssl_session_tickets off;
|
||||
ssl_prefer_server_ciphers on;
|
||||
add_header Strict-Transport-Security max-age=15768000;
|
||||
{% do our_headers.append('Strict-Transport-Security') %}
|
||||
sendfile {% if server.sendfile is defined and server.sendfile == '1' %}On{% else %}Off{% endif %};
|
||||
{% endif %}
|
||||
server_name {{ server.servername.replace(',', ' ') }};
|
||||
|
||||
@@ -157,6 +157,9 @@ location {{ location.matchtype }} {{ location.urlpattern }} {
|
||||
proxy_store {% if upstream.store == '1' %}on{% else %}off{% endif %};
|
||||
{% endif %}
|
||||
{% endif %}
|
||||
{% for our_header in our_headers %}
|
||||
proxy_hide_header {{ our_header }};
|
||||
{% endfor %}
|
||||
{% endif %}
|
||||
{% endif %}
|
||||
|
||||
|
||||
@@ -1,18 +1,24 @@
|
||||
{% if security_rule.referrer is defined %}
|
||||
{% do our_headers.append('Referrer-Policy') %}
|
||||
add_header Referrer-Policy "{{ security_rule.referrer }}" always;
|
||||
{% endif %}
|
||||
{% if security_rule.xssprotection is defined %}
|
||||
{% do our_headers.append('X-XSS-Protection') %}
|
||||
add_header X-XSS-Protection "{{ security_rule.xssprotection }}" always;
|
||||
{% endif %}
|
||||
{% if security_rule.content_type_options is defined and security_rule.content_type_options == '1' %}
|
||||
{% do our_headers.append('X-Content-Type-Options') %}
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
{% endif %}
|
||||
{% if security_rule.strict_transport_security_time is defined %}
|
||||
{% do our_headers.append('Strict-Transport-Security') %}
|
||||
add_header Strict-Transport-Security "{{ security_rule.strict_transport_security_time }}{%
|
||||
if security_rule.strict_transport_security_include_subdomains is defined and
|
||||
security_rule.strict_transport_security_include_subdomains == '1' %}; includeSubDomains{% endif %}" always;
|
||||
{% endif %}
|
||||
{% if security_rule.hpkp_keys is defined and security_rule.hpkp_time is defined %}
|
||||
{% do our_headers.append('Public-Key-Pins') %}
|
||||
{% do our_headers.append('Public-Key-Pins-Report-Only') %}
|
||||
add_header Public-Key-Pins{% if security_rule.hpkp_report_only is defined and security_rule.hpkp_report_only == '1'
|
||||
%}-Report-Only{% endif %} "{% for key in security_rule.hpkp_keys.split(',')
|
||||
%}pin-sha256={{ key }}; {% endfor %}max-age={{ security_rule.hpkp_time }}{%
|
||||
@@ -59,6 +65,8 @@
|
||||
{% endif %}
|
||||
{% endif %}
|
||||
{% endfor %}
|
||||
{% do our_headers.append('Content-Security-Policy') %}
|
||||
{% do our_headers.append('Content-Security-Policy-Report-Only') %}
|
||||
add_header Content-Security-Policy{% if security_rule.csp_report_only %}-Report-Only{% endif %} "{%
|
||||
for key, value in hash_csp.items() %}{{ key }} {{ value|join(' ') }}; {% endfor %}{#
|
||||
#} report-uri /opnsense-report-csp-violation" always;
|
||||
|
||||
Reference in New Issue
Block a user