Commit graph

65 commits

Author SHA1 Message Date
Kijin Sung
cfc7cfd53b Block direct access to cached files in files/faceOff 2024-01-20 00:27:11 +09:00
Kijin Sung
fbc5564247 Prevent direct access to .blade.php templates 2023-10-20 23:15:21 +09:00
Kijin Sung
3ea1567fda Stop allowing access to .php files under files/cache/
files/cache/document_category/<module_srl>.xml.php 파일에 직접 접근할 필요가
없게 되었으므로, files/cache/ 폴더 전체의 .php 파일 접근을 금지해도 무방함.
2023-08-07 00:35:40 +09:00
Kijin Sung
baddbd3cba Support XE-compatible rewrite rules 2020-06-12 14:16:36 +09:00
Kijin Sung
e6305404c5 Add rewrite rules for downloading 2020-03-15 00:51:15 +09:00
Kijin Sung
f81a98cde3 Update .htaccess like XE 1.11.3 2019-03-26 10:58:14 +09:00
Kijin Sung
56f20e84c0 Remove unnecessary exception from .htaccess
오래된 매뉴얼은 삭제되었으므로 .htaccess에서 예외를 삭제함.
2018-10-09 09:58:16 +09:00
Kijin Sung
0a518910e6 Reorder rewrite rules in .htaccess
Bug reported in https://www.xetown.com/qna/788451
2017-11-08 11:33:49 +09:00
Kijin Sung
1feb506b3c Remove vid from URL rewrite list 2017-03-13 14:54:50 +09:00
Kijin Sung
4d03f70d0a Prevent direct access to cache files under files/member_extra_info 2017-02-27 16:24:35 +09:00
Kijin Sung
e7511cdead Fix #713 missing rewrite rule for category URL 2017-02-14 10:42:21 +09:00
Kijin Sung
ba8ff52904 Do not interfere with letsencrypt access to .well-known 2016-07-05 22:42:22 +09:00
Kijin Sung
ffd6c42447 Add rewrite rules to map nonexistent minified scripts to original file 2016-06-29 19:41:30 +09:00
Kijin Sung
ba28484545 Update .htaccess and nginx rewrite rules 2016-06-29 16:49:36 +09:00
Kijin Sung
1c55d8b411 Allow access to HTML files in common/manual folder 2016-06-22 23:37:25 +09:00
Kijin Sung
e2828ed155 Improve precision and security of .htaccess and nginx configuration
- Block direct access to HTML and XML files in all modules, themes, etc.
- Block direct access to environment information in files/env/*
- Block direct access to dotfiles and other developer resources
- Block direct access to cache store
- Block PHP execution in upload directory (for additional protection)
- Ensure consitency between Apache and nginx rewrite rules
- Remove redundant rewrite rules
2016-06-18 13:16:02 +09:00
bnu
fc8c62500c common 폴더의 .html 파일에 대한 접근 제한을 추가로 적용 2016-06-16 22:37:10 +09:00
conory
0a89dffa5a XE표기를 Rhymix로 변경 2016-01-25 18:10:15 +09:00
Kijin Sung
676f17fb71 Fix #145 broken redirect from admin folder to admin module 2016-01-22 11:53:39 +09:00
misol
f70ce644ce Close Connection when there is no connection value.
git-svn-id: http://xe-core.googlecode.com/svn/branches/maserati@13161 201d5d3c-b55e-5fd7-737f-ddc643e51545
2013-09-25 15:29:32 +00:00
florinutz
5e8d7ab436 Issue 175: Routing
git-svn-id: http://xe-core.googlecode.com/svn/branches/luminous@12035 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-11-01 16:39:23 +00:00
flyskyko
3f6fc389a7 issue 1763, fixed a bug that trackback is not work.
git-svn-id: http://xe-core.googlecode.com/svn/branches/luminous@11309 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-09-18 09:06:10 +00:00
misol
aa3e2b7ac5 Unintended action loss fix about Issue 2166.
DrEditor was lost their function because, it can not load 'blank.html' file. This revision fix the loss with rewrite condition. Thanks to BNU.

git-svn-id: http://xe-core.googlecode.com/svn/branches/1.5.3.2@11084 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-08-25 16:55:44 +00:00
misol
18e2cec3d2 Remove 'tpl' directory *.html files from reserving template source file list.
git-svn-id: http://xe-core.googlecode.com/svn/branches/1.5.3.1@11039 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-08-17 08:28:02 +00:00
misol
bf6bb59905 Issue 2166 reserve XE Template Source Files (*.html)
git-svn-id: http://xe-core.googlecode.com/svn/branches/1.5.3.1@10924 201d5d3c-b55e-5fd7-737f-ddc643e51545
2012-07-22 15:51:09 +00:00
taggon
43fe125696 issue 165: Preserve queries in URL
git-svn-id: http://xe-core.googlecode.com/svn/branches/1.5.0@9588 201d5d3c-b55e-5fd7-737f-ddc643e51545
2011-10-11 10:03:28 +00:00
taggon
3cc0db3bc0 issue 28 : Remove ungreedy rule (.*?) because old webservers don't support it.
It can occure '500 internal server error'.


git-svn-id: http://xe-core.googlecode.com/svn/branches/1.5.0@8473 201d5d3c-b55e-5fd7-737f-ddc643e51545
2011-06-10 02:50:34 +00:00
taggon
ac19dd52f9 Fix a bug related to issue 28 :
1. Make the rule ungreedy.
2. The rule won't match 'common'.


git-svn-id: http://xe-core.googlecode.com/svn/branches/1.5.0@8466 201d5d3c-b55e-5fd7-737f-ddc643e51545
2011-06-09 01:25:49 +00:00
khongchi
47d4ddf413 #19605418 domain/mid/document_srl로 접속시 위젯스타일 css를 불러오지 못하는 오류 해결
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@8142 201d5d3c-b55e-5fd7-737f-ddc643e51545
2011-03-08 00:58:31 +00:00
bnu
9e39a22f16 r8068에서 추가된 스킨 파일에 대한 처리를 제거
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@8110 201d5d3c-b55e-5fd7-737f-ddc643e51545
2011-02-17 08:24:20 +00:00
bnu
76f38abc62 r8068에서 추가된 스킨 파일에 대한 처리를 제거(주석처리)
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@8109 201d5d3c-b55e-5fd7-737f-ddc643e51545
2011-02-17 08:22:43 +00:00
bnu
7763eb941a #19506256 모듈, 애드온, 위젯의 queries, schemas에 포함된 xml 파일 및 스킨에 대한 접근 제한 추가
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@8068 201d5d3c-b55e-5fd7-737f-ddc643e51545
2011-02-01 16:05:54 +00:00
ngleader
176f66d88b rewrite rul에 m.layouts 추가
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@7850 201d5d3c-b55e-5fd7-737f-ddc643e51545
2010-11-18 02:12:21 +00:00
zero
4f0ddc76fa rewriteRule 수정
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@7849 201d5d3c-b55e-5fd7-737f-ddc643e51545
2010-11-18 02:05:23 +00:00
haneul
17631ad77f #18626368 : remove vid+document_srl rule (it's override same rule for mid+document_srl)
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@7187 201d5d3c-b55e-5fd7-737f-ddc643e51545
2010-01-20 05:26:14 +00:00
taggon
7352faa914 #18573849 일부 오래된 버전의 Apache에서 \w, \d 등의 정규식 표현을 이해하지 못하는 부분 수정
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@7078 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-12-29 07:33:23 +00:00
taggon
d25a9c3c79 #18525697 정적 파일은 파일이 없을 때만 규칙을 적용하도록 하고, vid, mid는 폴더가 존재하지 않을 경우에만 적용하도록 함.
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@7053 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-12-18 07:50:42 +00:00
taggon
7610bf973a #18552591 일부 오래된 Apache 서버에서 수정된 .htaccess가 Internal Server Error를 발생시키는 버그 수정
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@7052 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-12-18 04:53:02 +00:00
taggon
3f691442ad #18536166 Rewrite 규칙 최적화
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@7023 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-12-10 06:19:02 +00:00
zero
1789ad6e94 htaccess 에 layout의 html 파일을 보호하기 위한 코드를 추가
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@6648 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-06-23 01:39:43 +00:00
zero
9be092776a trackback rewrite rule 적용된 .htaccess 커밋
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@6251 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-05-04 01:13:52 +00:00
zero
650b2a32e1 rewrite rul 사용시 첨부이미지/멤버이미지/메뉴버튼이미지등이 제대로 나타나지 않는 오류 수정
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@6077 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-04-10 02:12:42 +00:00
zero
5e883170bb 1. 가상사이트의 구분 변수명을 sid에서 vid로 변경
2. rank_count 위젯에서 그룹이 지정되지 않았을 경우 해당 가상 사이트의 모든 그룹을 대상으로 하도록 코드 수정


git-svn-id: http://xe-core.googlecode.com/svn/sandbox@6053 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-04-09 00:22:43 +00:00
zero
bb97446dfc Virtual Site 생성시 도메인 단위(서브도메인 또는 독립 도메인)이 아닌 ID 형식으로 생성 가능하도록 기능 개선.
SID 로 불리는 이 사이트ID는 MID와 중복이 불가능함.


git-svn-id: http://xe-core.googlecode.com/svn/sandbox@6051 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-04-08 10:10:17 +00:00
ngleader
61851f1dfe css 및 js 호출순서 조정기능 추가
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@5785 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-03-06 05:33:56 +00:00
misol
995b3f1af2 git-svn-id: http://xe-core.googlecode.com/svn/sandbox@5365 201d5d3c-b55e-5fd7-737f-ddc643e51545 2009-01-15 12:10:27 +00:00
misol
c9edb15e8d #17625594 Atom 1.0 지원, rss포맷 다양화
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@5312 201d5d3c-b55e-5fd7-737f-ddc643e51545
2009-01-11 05:50:21 +00:00
zero
dcd61fefe2 .htaccess의 rewrite rule 오류로 년/월별 게시글 목록 링크로 접근시 대상을 찾을 수 없다는 오류 수정
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@4398 201d5d3c-b55e-5fd7-737f-ddc643e51545
2008-07-21 08:24:27 +00:00
zero
0fddaf252f tool 기능을 개선하여 전체 tool관리 가능하도록 변경(주소/tools 로 접속하여 선택). 빈 디렉토리 삭제 기능 추가
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@4378 201d5d3c-b55e-5fd7-737f-ddc643e51545
2008-07-17 03:30:49 +00:00
zero
bdc194ab1d 캐시를 지우는 외부 툴 스크립트 추가. 파일을 핸들링할때 경로를 제대로 찾아서 처리할 수 있도록 코드 수정
git-svn-id: http://xe-core.googlecode.com/svn/sandbox@4331 201d5d3c-b55e-5fd7-737f-ddc643e51545
2008-06-27 08:23:23 +00:00