From 74ffca22ffd6adcffb8dc8d54c85daeba7d194b2 Mon Sep 17 00:00:00 2001 From: MickLesk <47820557+MickLesk@users.noreply.github.com> Date: Tue, 6 Oct 2026 16:06:54 +0200 Subject: [PATCH] Webtrees: stop serving data/ and the source folders directly Caddy served all of /opt/webtrees through file_server, so media under data/media could be fetched by URL without passing webtrees' privacy rules. webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the folders webtrees' own nginx guide keeps private, plus dotfiles. update_script adds the rule to existing Caddyfiles on every update, not only when a new release is out, and keeps the old file if the result fails caddy validate. --- ct/webtrees.sh | 14 ++++++++++++++ install/webtrees-install.sh | 3 +++ 2 files changed, 17 insertions(+) diff --git a/ct/webtrees.sh b/ct/webtrees.sh index 9c0ecc2c7..58b958f20 100644 --- a/ct/webtrees.sh +++ b/ct/webtrees.sh @@ -31,6 +31,20 @@ function update_script() { exit fi + if ! grep -q "@private" /etc/caddy/Caddyfile; then + msg_info "Blocking direct access to webtrees data" + cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak + sed -i '\|root \* /opt/webtrees|a\ @private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*\n respond @private 403' /etc/caddy/Caddyfile + if grep -q "@private" /etc/caddy/Caddyfile && caddy validate --config /etc/caddy/Caddyfile &>/dev/null; then + rm -f /etc/caddy/Caddyfile.bak + systemctl reload-or-restart caddy + msg_ok "Blocked direct access to webtrees data" + else + mv /etc/caddy/Caddyfile.bak /etc/caddy/Caddyfile + msg_warn "Could not patch /etc/caddy/Caddyfile - deny /data/ there by hand" + fi + fi + if check_for_gh_release "webtrees" "fisharebest/webtrees"; then msg_info "Stopping Service" PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;') diff --git a/install/webtrees-install.sh b/install/webtrees-install.sh index 410a7a24e..87d0a4860 100644 --- a/install/webtrees-install.sh +++ b/install/webtrees-install.sh @@ -36,6 +36,9 @@ PHP_SOCK=$(get_php_fpm_socket) cat </etc/caddy/Caddyfile :80 { root * /opt/webtrees + # Caddy ignores data/.htaccess; media must go through webtrees so its privacy rules apply. + @private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.* + respond @private 403 php_fastcgi unix/${PHP_SOCK} file_server encode gzip