[add] added 403 catchall for invalid domains

This commit is contained in:
2020-06-06 17:30:19 -04:00
parent a3f5fc413f
commit 9378ae4a00
3 changed files with 29 additions and 1 deletions

View File

@@ -261,6 +261,9 @@ function main()
# load env variable with domains
env_domain_file "$domain_file"
# create nixdomain cert for nginx if none exists (used for direct access)
init_cert "nixdomain"
# create temp certs for domains if none exists
# nginx need certs to start
read_file domain_init "$domain_file"

View File

@@ -199,6 +199,11 @@ function cert_exists()
[ -f "$cert_path/fullchain.pem" ]
}
function dummy_cert_exists()
{
cert_exists 0 nixdomain
}
function certs_daemon()
{
(
@@ -242,7 +247,7 @@ function nginx_handler()
# wait for certs to exist before starting nginx
# just have nginx crash after n retries (default 10)
while ! read_file cert_exists "$domain_file" && [ "$retries" -lt "$server_retries" ]; do
while ! read_file cert_exists "$domain_file" && ! dummy_cert_exists && [ "$retries" -lt "$server_retries" ]; do
log nginx_handler "Waiting for certs to be created"
retries=$(( retries+1 ))
sleep_wait 1

View File

@@ -40,6 +40,26 @@ http {
}
}
# catch all non domains
server {
listen 8443 ssl;
# prevent redirecting to 8080 port
# (e.g. when trailing slash is missed)
port_in_redirect off;
server_name "";
ssl_certificate /service/ssl/nixdomain/fullchain.pem;
ssl_certificate_key /service/ssl/nixdomain/privkey.pem;
location / {
deny all;
return 403;
}
}
# the following variable is automatically populated via entrypoint.sh
#<SERVER>