Block public access to .git directory (leaked live GitHub PAT)

The docRoot is the git working tree, so .git/ was directly downloadable
over HTTPS (curl https://orbis.orbishosting.com/.git/config returned 200),
exposing the origin remote URL with an embedded GitHub personal access
token in plaintext. Added a .htaccess denying dotfiles/.git and a
matching OpenLiteSpeed vhost context as defense in depth. The exposed
token should be revoked/rotated on GitHub regardless of this fix.
This commit is contained in:
2026-07-04 14:17:35 -05:00
parent b9ebc760e8
commit 8ad58278d0
2 changed files with 14 additions and 0 deletions
+9
View File
@@ -0,0 +1,9 @@
# Block direct web access to the .git directory and other dotfiles.
# The .git folder lives inside public_html (docRoot) and was found to be
# directly downloadable over HTTPS (e.g. https://orbis.orbishosting.com/.git/config),
# which leaked a live GitHub personal access token embedded in the remote URL.
RedirectMatch 404 /\.git
<FilesMatch "^\.">
Require all denied
</FilesMatch>
+5
View File
@@ -62,6 +62,11 @@ rewrite {
autoLoadHtaccess 1
}
context /.git {
location /dev/null
allowBrowse 0
}
context /.well-known/acme-challenge {
location /usr/local/lsws/Example/html/.well-known/acme-challenge
allowBrowse 1