From 164197ec9c98e6d1481229d19f53c449566501d4 Mon Sep 17 00:00:00 2001 From: hrupi Date: Wed, 18 Sep 2024 00:12:03 +0300 Subject: [PATCH] update default redirect --- docker-compose.yml | 5 ----- sites-enabled/default.conf | 3 --- sites-enabled/http_redirect.conf | 17 ++++++++++++++--- 3 files changed, 14 insertions(+), 11 deletions(-) diff --git a/docker-compose.yml b/docker-compose.yml index 43ec88f..d2b80a5 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -20,11 +20,6 @@ services: ports: - 80:80 - 443:443 - - 60180:60180 - - 60280:60280 - - 60380:60380 - - 60480:60480 - - 64443:64443 networks: local_net: diff --git a/sites-enabled/default.conf b/sites-enabled/default.conf index febd5ed..021ff17 100644 --- a/sites-enabled/default.conf +++ b/sites-enabled/default.conf @@ -1,7 +1,4 @@ server { - # listen 80 default_server; - # listen [::]:80 default_server; - listen 443 ssl default_server; listen [::]:443 ssl default_server; diff --git a/sites-enabled/http_redirect.conf b/sites-enabled/http_redirect.conf index 00e9c6f..d34c3d7 100644 --- a/sites-enabled/http_redirect.conf +++ b/sites-enabled/http_redirect.conf @@ -1,5 +1,16 @@ +#Для сложных маршрутов с регулярным выражением +#Требует ресурсы на обработку регулярного выражения +# server { +# listen 80 default_server; +# listen [::]:80 default_server; +# rewrite ^(.*) https://$host$1 permanent; +# } + +#Не требует ресурсов для обработки запроса +#Уязвим для атак через Host-заголовок server { - listen 80 default_server; - listen [::]:80 default_server; - rewrite ^(.*) https://$host$1 permanent; + listen 80; + listen [::]:80; + server_name _; + return 301 https://$host$request_uri; } \ No newline at end of file