Compare commits

...

7 Commits

Author SHA1 Message Date
community-scripts-pr-app[bot]
48706f41d5 Update CHANGELOG.md (#17730)
Some checks are pending
Create Changelog Pull Request / update-changelog-pull-request (push) Waiting to run
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Waiting to run
Sync ct/install to Incus / dispatch (push) Waiting to run
Update script timestamp on .sh changes / update-script-timestamp (push) Waiting to run
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 15:39:40 +00:00
community-scripts-pr-app[bot]
017691457a Update CHANGELOG.md (#17729)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:29:29 +00:00
community-scripts-pr-app[bot]
17f5ac84e5 Update CHANGELOG.md (#17728)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:27:31 +00:00
community-scripts-pr-app[bot]
0b0ad2e9bd Update CHANGELOG.md (#17727)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:27:19 +00:00
community-scripts-pr-app[bot]
78a4d809c7 Update CHANGELOG.md (#17726)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:26:51 +00:00
CanbiZ (MickLesk)
36078aa896 Webtrees: stop serving data/ and the source folders directly (#17724)
Caddy served all of /opt/webtrees through file_server, so media under
data/media could be fetched by URL without passing webtrees' privacy rules.
webtrees only protects data/ with an .htaccess, which Caddy ignores. Deny the
folders webtrees' own nginx guide keeps private, plus dotfiles.

update_script adds the rule to existing Caddyfiles on every update, not only
when a new release is out, and keeps the old file if the result fails
caddy validate.
2026-10-06 16:26:21 +02:00
community-scripts-pr-app[bot]
69bbf389f3 Update CHANGELOG.md (#17725)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-06 14:23:09 +00:00
3 changed files with 28 additions and 1 deletions

View File

@@ -565,9 +565,19 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
- Pricebuddy ([#17708](https://github.com/community-scripts/ProxmoxVE/pull/17708))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Webtrees: stop serving data/ and the source folders directly [@MickLesk](https://github.com/MickLesk) ([#17724](https://github.com/community-scripts/ProxmoxVE/pull/17724))
### 💾 Core
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
- Incus: check the architecture on Incus hosts too [@MickLesk](https://github.com/MickLesk) ([core#113](https://github.com/community-scripts/core/pull/113))
- Incus: Pass the app's var_* settings into Incus containers [@MickLesk](https://github.com/MickLesk) ([core#112](https://github.com/community-scripts/core/pull/112))
- Incus: stub storage_content_check on Incus [@MickLesk](https://github.com/MickLesk) ([core#104](https://github.com/community-scripts/core/pull/104))
- Incus: map Proxmox template versions to Incus image names [@MickLesk](https://github.com/MickLesk) ([core#111](https://github.com/community-scripts/core/pull/111))
- Incus: read storage names from .vars files [@MickLesk](https://github.com/MickLesk) ([core#110](https://github.com/community-scripts/core/pull/110))
- Incus: show the spinner inside containers again [@MickLesk](https://github.com/MickLesk) ([core#109](https://github.com/community-scripts/core/pull/109))
- Incus: set the hostname with sh, so it works before bash is installed [@MickLesk](https://github.com/MickLesk) ([core#102](https://github.com/community-scripts/core/pull/102))
- Incus: reserve a plain address on Incus, leave the gateway to the network [@MickLesk](https://github.com/MickLesk) ([core#101](https://github.com/community-scripts/core/pull/101))

View File

@@ -31,6 +31,20 @@ function update_script() {
exit
fi
if ! grep -q "@private" /etc/caddy/Caddyfile; then
msg_info "Blocking direct access to webtrees data"
cp /etc/caddy/Caddyfile /etc/caddy/Caddyfile.bak
sed -i '\|root \* /opt/webtrees|a\ @private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*\n respond @private 403' /etc/caddy/Caddyfile
if grep -q "@private" /etc/caddy/Caddyfile && caddy validate --config /etc/caddy/Caddyfile &>/dev/null; then
rm -f /etc/caddy/Caddyfile.bak
systemctl reload-or-restart caddy
msg_ok "Blocked direct access to webtrees data"
else
mv /etc/caddy/Caddyfile.bak /etc/caddy/Caddyfile
msg_warn "Could not patch /etc/caddy/Caddyfile - deny /data/ there by hand"
fi
fi
if check_for_gh_release "webtrees" "fisharebest/webtrees"; then
msg_info "Stopping Service"
PHP_VER=$(php -r 'echo PHP_MAJOR_VERSION . "." . PHP_MINOR_VERSION;')

View File

@@ -36,6 +36,9 @@ PHP_SOCK=$(get_php_fpm_socket)
cat <<EOF >/etc/caddy/Caddyfile
:80 {
root * /opt/webtrees
# Caddy ignores data/.htaccess; media must go through webtrees so its privacy rules apply.
@private path /app/* /data/* /modules_v4/* /resources/* /vendor/* /.*
respond @private 403
php_fastcgi unix/${PHP_SOCK}
file_server
encode gzip