Harden .git/db block: use REQUEST_URI matching, direct RewriteRule patterns not reliably honored

This commit is contained in:
2026-07-04 15:56:59 -05:00
parent 0dfcfa2f7e
commit 982a5dc5ff
2 changed files with 9 additions and 3 deletions
+5 -2
View File
@@ -16,8 +16,11 @@ RewriteBase /
# Block access to version control metadata and the raw DB schema dump. # Block access to version control metadata and the raw DB schema dump.
# These were previously reachable directly over HTTP (e.g. /.git/config, # These were previously reachable directly over HTTP (e.g. /.git/config,
# /db/schema.sql) and leaked repo/DB internals - deny them outright. # /db/schema.sql) and leaked repo/DB internals - deny them outright.
RewriteRule ^\.git(/|$) - [F,L] # Note: a direct RewriteRule pattern (no leading slash) was found NOT to be
RewriteRule ^db/ - [F,L] # honored consistently on this LiteSpeed setup for root-level paths; matching
# on REQUEST_URI via RewriteCond is what's confirmed to work.
RewriteCond %{REQUEST_URI} ^/(\.git|db/)
RewriteRule .* - [F,L]
# API Routes - Direct to PHP backend # API Routes - Direct to PHP backend
RewriteCond %{REQUEST_URI} ^/api/ RewriteCond %{REQUEST_URI} ^/api/
+4 -1
View File
@@ -8,7 +8,10 @@
# Block direct access to config.php / .env - this was reachable at # Block direct access to config.php / .env - this was reachable at
# /api/config.php in production (200 OK) despite the FilesMatch/Require # /api/config.php in production (200 OK) despite the FilesMatch/Require
# rule below, which LiteSpeed appears not to honor from .htaccess here. # rule below, which LiteSpeed appears not to honor from .htaccess here.
RewriteRule ^(config\.php|\.env)$ - [F,L] # Matching on REQUEST_URI (not a direct RewriteRule pattern) is what's
# confirmed to actually work on this LiteSpeed setup.
RewriteCond %{REQUEST_URI} /(config\.php|\.env)$
RewriteRule .* - [F,L]
# Route all requests to index.php # Route all requests to index.php
RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-f