mirror of
https://github.com/myronblair/epictravelexpeditions
synced 2026-07-28 00:43:14 -05:00
0dfcfa2f7e
- mailer.php: re-enable TLS certificate verification for CyberMail API calls (was CURLOPT_SSL_VERIFYPEER => false, exposing outbound mail traffic to MITM). - .htaccess / api/.htaccess: block direct HTTP access to .git/, db/, and api/config.php via mod_rewrite [F] rules. Confirmed live that /.git/config, /.git/logs/HEAD, and /db/schema.sql were all directly downloadable (200 OK with real content) - .git exposure leaks the repo's embedded GitHub token and full history; schema.sql leaks the DB layout. Also drops the dead "/setup -> setup_password.php" rewrite, since that file was already deleted from production. - index.php: remove the 'download' route, which required a api/download.php that has never existed in this repo - confirmed live that GET /api/download returns a fatal 500. - functions.php / upload.php / testimonials.php: extract the duplicated image-upload validation/move logic (MIME check, size check, UUID rename, move_uploaded_file) into one handleImageUpload() helper used by both upload endpoints. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
64 lines
1.7 KiB
ApacheConf
64 lines
1.7 KiB
ApacheConf
### Rewrite Rules Added by CyberPanel Rewrite Rule Generator
|
|
|
|
RewriteEngine On
|
|
RewriteCond %{HTTPS} !=on
|
|
RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1 [R,L]
|
|
|
|
### End CyberPanel Generated Rules.
|
|
|
|
# Epic Travel & Expeditions - CyberPanel LiteSpeed Configuration
|
|
DirectoryIndex index.html index.php
|
|
|
|
<IfModule mod_rewrite.c>
|
|
RewriteEngine On
|
|
RewriteBase /
|
|
|
|
# Block access to version control metadata and the raw DB schema dump.
|
|
# These were previously reachable directly over HTTP (e.g. /.git/config,
|
|
# /db/schema.sql) and leaked repo/DB internals - deny them outright.
|
|
RewriteRule ^\.git(/|$) - [F,L]
|
|
RewriteRule ^db/ - [F,L]
|
|
|
|
# API Routes - Direct to PHP backend
|
|
RewriteCond %{REQUEST_URI} ^/api/
|
|
RewriteRule ^api/(.*)$ api/api/$1 [L,QSA]
|
|
|
|
# Static files and directories - serve directly
|
|
RewriteCond %{REQUEST_FILENAME} -f [OR]
|
|
RewriteCond %{REQUEST_FILENAME} -d
|
|
RewriteRule ^ - [L]
|
|
|
|
# React Router - All other routes to index.html
|
|
RewriteRule ^ index.html [L]
|
|
</IfModule>
|
|
|
|
# Security Headers
|
|
<IfModule mod_headers.c>
|
|
Header set X-Content-Type-Options "nosniff"
|
|
Header set X-Frame-Options "SAMEORIGIN"
|
|
Header set X-XSS-Protection "1; mode=block"
|
|
</IfModule>
|
|
|
|
# Enable CORS for API
|
|
<FilesMatch "\.(php)$">
|
|
Header set Access-Control-Allow-Origin "*"
|
|
Header set Access-Control-Allow-Methods "GET, POST, PUT, DELETE, OPTIONS"
|
|
Header set Access-Control-Allow-Headers "Content-Type, Authorization"
|
|
</FilesMatch>
|
|
|
|
# Disable directory browsing
|
|
Options -Indexes +FollowSymLinks
|
|
|
|
# PHP Settings
|
|
<IfModule mod_php.c>
|
|
php_value upload_max_filesize 10M
|
|
php_value post_max_size 10M
|
|
php_value memory_limit 256M
|
|
php_value max_execution_time 300
|
|
</IfModule>
|
|
|
|
# Force use of index.html
|
|
<IfModule mod_dir.c>
|
|
DirectoryIndex index.html index.php
|
|
</IfModule>
|