|
#user nobody; |
|
worker_processes 1; |
|
|
|
#error_log logs/error.log; |
|
#error_log logs/error.log notice; |
|
#error_log logs/error.log info; |
|
error_log /dev/stdout info; |
|
|
|
#pid logs/nginx.pid; |
|
|
|
|
|
events { |
|
worker_connections 1024; |
|
} |
|
|
|
env SECRET_TOKEN; |
|
|
|
http { |
|
include mime.types; |
|
default_type application/octet-stream; |
|
|
|
#log_format main '$remote_addr - $remote_user [$time_local] "$request" ' |
|
# '$status $body_bytes_sent "$http_referer" ' |
|
# '"$http_user_agent" "$http_x_forwarded_for"'; |
|
|
|
#access_log logs/access.log main; |
|
access_log /dev/stdout; |
|
|
|
sendfile on; |
|
#tcp_nopush on; |
|
|
|
#keepalive_timeout 0; |
|
keepalive_timeout 65; |
|
|
|
#gzip on; |
|
|
|
mruby_init_code ' |
|
def hmac_secure_compare(a, b) |
|
## see Rack::Utils.secure_compare |
|
return false unless a.bytesize == b.bytesize |
|
l = a.unpack("C*") |
|
r, i = 0, -1 |
|
b.each_byte { |v| r |= v ^ l[i+=1] } |
|
r == 0 |
|
end |
|
'; |
|
|
|
upstream app { |
|
server 127.0.0.1:8080; |
|
} |
|
|
|
server { |
|
listen 80; |
|
server_name localhost; |
|
|
|
#charset koi8-r; |
|
|
|
#access_log logs/host.access.log main; |
|
|
|
#location / { |
|
# root html; |
|
# index index.html index.htm; |
|
#} |
|
|
|
location / { |
|
mruby_access_handler_code ' |
|
r = Nginx::Request.new |
|
begin |
|
Nginx.errlogger Nginx::LOG_ERR, "r.body: #{r.body} / X-Hub-Signature: #{r.headers_in[%q!X-Hub-Signature!]}" |
|
signature = "sha1=" + Digest::HMAC.hexdigest(r.body, ENV["SECRET_TOKEN"], Digest::SHA1) |
|
if hmac_secure_compare(signature, r.headers_in["X-Hub-Signature"]) |
|
Nginx.return Nginx::DECLINED |
|
else |
|
Nginx.errlogger Nginx::LOG_ERR, "signature missmatch, Digest::HMAC.hexdigest(r.body, ...) = #{signature}" |
|
Nginx.return Nginx::HTTP_FORBIDDEN |
|
end |
|
rescue => e |
|
Nginx.errlogger Nginx::LOG_ERR, "e: #{e.inspect}" |
|
Nginx.return Nginx::HTTP_FORBIDDEN |
|
end |
|
'; |
|
#mruby_content_handler_code ' |
|
# r = Nginx::Request.new |
|
# Nginx.echo "server ip: #{Nginx::Connection.new.local_ip}: hello ngx_mruby world." |
|
# Nginx.echo "body: #{r.body.inspect}" |
|
# Nginx.echo system(r.body) |
|
#'; |
|
proxy_set_header X-Real-IP $remote_addr; |
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; |
|
proxy_set_header Host $http_host; |
|
proxy_set_header X-Forwarded-Proto $scheme; |
|
proxy_pass http://app; |
|
} |
|
|
|
#error_page 404 /404.html; |
|
|
|
# redirect server error pages to the static page /50x.html |
|
# |
|
error_page 500 502 503 504 /50x.html; |
|
location = /50x.html { |
|
root html; |
|
} |
|
|
|
# proxy the PHP scripts to Apache listening on 127.0.0.1:80 |
|
# |
|
#location ~ \.php$ { |
|
# proxy_pass http://127.0.0.1; |
|
#} |
|
|
|
# pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000 |
|
# |
|
#location ~ \.php$ { |
|
# root html; |
|
# fastcgi_pass 127.0.0.1:9000; |
|
# fastcgi_index index.php; |
|
# fastcgi_param SCRIPT_FILENAME /scripts$fastcgi_script_name; |
|
# include fastcgi_params; |
|
#} |
|
|
|
# deny access to .htaccess files, if Apache's document root |
|
# concurs with nginx's one |
|
# |
|
#location ~ /\.ht { |
|
# deny all; |
|
#} |
|
} |
|
|
|
|
|
# another virtual host using mix of IP-, name-, and port-based configuration |
|
# |
|
#server { |
|
# listen 8000; |
|
# listen somename:8080; |
|
# server_name somename alias another.alias; |
|
|
|
# location / { |
|
# root html; |
|
# index index.html index.htm; |
|
# } |
|
#} |
|
|
|
|
|
# HTTPS server |
|
# |
|
#server { |
|
# listen 443 ssl; |
|
# server_name localhost; |
|
|
|
# ssl_certificate cert.pem; |
|
# ssl_certificate_key cert.key; |
|
|
|
# ssl_session_cache shared:SSL:1m; |
|
# ssl_session_timeout 5m; |
|
|
|
# ssl_ciphers HIGH:!aNULL:!MD5; |
|
# ssl_prefer_server_ciphers on; |
|
|
|
# location / { |
|
# root html; |
|
# index index.html index.htm; |
|
# } |
|
#} |
|
|
|
} |