portal-apache2.conf 3.29 KB
Newer Older
1 2 3 4 5 6 7
#====================================================================
# Apache configuration for LemonLDAP::NG Portal
#====================================================================

# Uncomment this if no previous NameVirtualHost declaration
#NameVirtualHost __VHOSTLISTEN__

8 9 10 11
# To insert LLNG user id in Apache logs, declare this format and use it in
# CustomLog directive
#LogFormat "%v:%p %h %l %{Lm-Remote-User}o %t \"%r\" %>s %O" llng

12 13 14
# Portal Virtual Host (auth.__DNSDOMAIN__)
<VirtualHost __VHOSTLISTEN__>
    ServerName auth.__DNSDOMAIN__
15 16
    # See above to set LLNG user id in Apache logs
    #CustomLog /var/log/apache2/portal.log llng
17

18
    # DocumentRoot (FCGI scripts)
19 20
    DocumentRoot __PORTALSITEDIR__
    <Directory __PORTALSITEDIR__>
Xavier Guimard's avatar
Xavier Guimard committed
21 22 23
        Order allow,deny
        Allow from all
        Options +ExecCGI +FollowSymLinks
24
    </Directory>
25
    RewriteEngine On
26 27 28 29
    # For performances, you can put static html files: simply put the HTML
    # result (example: /oauth2/checksession.html) as static file. Then
    # uncomment the following line.
    # RewriteCond "%{REQUEST_FILENAME}" "!\.html$"
30 31
    RewriteCond "%{REQUEST_FILENAME}" "!^/(?:(?:static|javascript|favicon).*|.*\.fcgi)$"
    RewriteRule "^/(.+)$" "/index.fcgi/$1" [PT]
32

Xavier Guimard's avatar
Xavier Guimard committed
33
    # Note that Content-Security-Policy header is generated by portal itself
34
    <Files *.fcgi>
Xavier Guimard's avatar
Xavier Guimard committed
35
        SetHandler fcgid-script
36 37
        #CGIPassAuth on
        Options +ExecCGI
38
        header unset Lm-Remote-User
Xavier Guimard's avatar
Xavier Guimard committed
39 40
    </Files>

41 42 43 44 45 46 47 48 49 50 51 52 53 54
    # Static files
    Alias /static/ __PORTALSTATICDIR__/
    <Directory __PORTALSTATICDIR__>
        Order allow,deny
        Allow from all
        Options +FollowSymLinks
    </Directory>
    <Location /static/>
        <IfModule mod_expires.c>
            ExpiresActive On
            ExpiresDefault "access plus 1 month"
        </IfModule>
    </Location>

55
    <IfModule mod_dir.c>
56
        DirectoryIndex index.fcgi index.html
57 58
    </IfModule>

59
    # REST/SOAP functions for sessions management (disabled by default)
60
    <Location /index.fcgi/adminSessions>
Xavier Guimard's avatar
Xavier Guimard committed
61 62
        Order deny,allow
        Deny from all
63
    </Location>
64

65
    # REST/SOAP functions for sessions access (disabled by default)
66
    <Location /index.fcgi/sessions>
Xavier Guimard's avatar
Xavier Guimard committed
67 68
        Order deny,allow
        Deny from all
69
    </Location>
70

71
    # REST/SOAP functions for configuration access (disabled by default)
72
    <Location /index.fcgi/config>
Xavier Guimard's avatar
Xavier Guimard committed
73 74
        Order deny,allow
        Deny from all
75
    </Location>
76

77
    # REST/SOAP functions for notification insertion (disabled by default)
78
    <Location /index.fcgi/notification>
Xavier Guimard's avatar
Xavier Guimard committed
79 80
        Order deny,allow
        Deny from all
81
    </Location>
82

83
    # Enabe compression
84 85
    <Location />
        <IfModule mod_deflate.c>
Xavier Guimard's avatar
Xavier Guimard committed
86 87 88 89 90 91
                AddOutputFilterByType DEFLATE text/html text/plain text/xml text/javascript text/css
                SetOutputFilter DEFLATE
                BrowserMatch ^Mozilla/4 gzip-only-text/html
                BrowserMatch ^Mozilla/4\.0[678] no-gzip
                BrowserMatch \bMSIE !no-gzip !gzip-only-text/html
                SetEnvIfNoCase Request_URI \.(?:gif|jpe?g|png)$ no-gzip dont-vary
92 93
        </IfModule>
        <IfModule mod_headers.c>
Xavier Guimard's avatar
Xavier Guimard committed
94
                Header append Vary User-Agent env=!dont-vary
95 96
        </IfModule>
    </Location>
97 98 99

    # Uncomment this if site if you use SSL only
    #Header set Strict-Transport-Security 15768000
100 101
</VirtualHost>