2016-01-30 21:12:40 +01:00
|
|
|
# Pi-hole: A black hole for Internet advertisements
|
2017-02-22 18:55:20 +01:00
|
|
|
# (c) 2017 Pi-hole, LLC (https://pi-hole.net)
|
|
|
|
# Network-wide ad blocking via your own hardware.
|
|
|
|
#
|
2017-10-03 13:05:06 +02:00
|
|
|
# Lighttpd config for Pi-hole
|
2016-01-30 21:12:40 +01:00
|
|
|
#
|
2017-02-22 18:55:20 +01:00
|
|
|
# This file is copyright under the latest version of the EUPL.
|
|
|
|
# Please see LICENSE file for your rights under this license.
|
|
|
|
|
2017-02-09 16:46:55 +01:00
|
|
|
###############################################################################
|
|
|
|
# FILE AUTOMATICALLY OVERWRITTEN BY PI-HOLE INSTALL/UPDATE PROCEDURE. #
|
|
|
|
# ANY CHANGES MADE TO THIS FILE AFTER INSTALL WILL BE LOST ON THE NEXT UPDATE #
|
|
|
|
# #
|
2017-10-09 10:53:22 +02:00
|
|
|
# CHANGES SHOULD BE MADE IN A SEPARATE CONFIG FILE: #
|
2017-02-09 16:46:55 +01:00
|
|
|
# /etc/lighttpd/external.conf #
|
|
|
|
###############################################################################
|
|
|
|
|
2015-06-07 06:27:43 +02:00
|
|
|
server.modules = (
|
2020-05-19 10:09:51 +02:00
|
|
|
"mod_access",
|
|
|
|
"mod_accesslog",
|
|
|
|
"mod_auth",
|
|
|
|
"mod_expire",
|
|
|
|
"mod_redirect",
|
|
|
|
"mod_setenv",
|
|
|
|
"mod_rewrite"
|
2015-06-07 06:27:43 +02:00
|
|
|
)
|
2015-10-17 19:04:49 +02:00
|
|
|
|
|
|
|
server.document-root = "/var/www/html"
|
2019-07-01 03:42:02 +02:00
|
|
|
server.error-handler-404 = "/pihole/index.php"
|
2015-06-07 06:27:43 +02:00
|
|
|
server.upload-dirs = ( "/var/cache/lighttpd/uploads" )
|
|
|
|
server.errorlog = "/var/log/lighttpd/error.log"
|
2020-04-03 19:05:59 +02:00
|
|
|
server.pid-file = "/run/lighttpd.pid"
|
2015-06-07 06:27:43 +02:00
|
|
|
server.username = "www-data"
|
|
|
|
server.groupname = "www-data"
|
|
|
|
server.port = 80
|
2017-02-09 16:46:55 +01:00
|
|
|
accesslog.filename = "/var/log/lighttpd/access.log"
|
|
|
|
accesslog.format = "%{%s}t|%V|%r|%s|%b"
|
2015-10-17 19:04:49 +02:00
|
|
|
|
2015-06-07 06:27:43 +02:00
|
|
|
index-file.names = ( "index.php", "index.html", "index.lighttpd.html" )
|
2017-09-21 23:47:37 +02:00
|
|
|
url.access-deny = ( "~", ".inc", ".md", ".yml", ".ini" )
|
2015-06-07 06:27:43 +02:00
|
|
|
static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" )
|
2015-10-17 19:04:49 +02:00
|
|
|
|
2020-05-19 10:09:51 +02:00
|
|
|
mimetype.assign = (
|
|
|
|
".ico" => "image/x-icon",
|
|
|
|
".jpeg" => "image/jpeg",
|
|
|
|
".jpg" => "image/jpeg",
|
|
|
|
".png" => "image/png",
|
|
|
|
".svg" => "image/svg+xml",
|
|
|
|
".css" => "text/css; charset=utf-8",
|
|
|
|
".html" => "text/html; charset=utf-8",
|
|
|
|
".js" => "text/javascript; charset=utf-8",
|
|
|
|
".json" => "application/json; charset=utf-8",
|
|
|
|
".map" => "application/json; charset=utf-8",
|
|
|
|
".txt" => "text/plain; charset=utf-8",
|
|
|
|
".eot" => "application/vnd.ms-fontobject",
|
|
|
|
".otf" => "font/otf",
|
|
|
|
".ttc" => "font/collection",
|
|
|
|
".ttf" => "font/ttf",
|
|
|
|
".woff" => "font/woff",
|
|
|
|
".woff2" => "font/woff2"
|
|
|
|
)
|
2019-06-24 20:38:03 +02:00
|
|
|
|
2021-01-22 20:23:59 +01:00
|
|
|
# Add user chosen options held in external file
|
|
|
|
# This uses include_shell instead of an include wildcard for compatibility
|
|
|
|
include_shell "cat external.conf 2>/dev/null"
|
|
|
|
|
2015-06-07 06:27:43 +02:00
|
|
|
# default listening port for IPv6 falls back to the IPv4 port
|
|
|
|
include_shell "/usr/share/lighttpd/use-ipv6.pl " + server.port
|
2017-10-03 13:05:06 +02:00
|
|
|
|
|
|
|
# Prevent Lighttpd from enabling Let's Encrypt SSL for every blocked domain
|
2017-05-02 09:24:07 +02:00
|
|
|
#include_shell "/usr/share/lighttpd/include-conf-enabled.pl"
|
2017-05-02 09:28:51 +02:00
|
|
|
include_shell "find /etc/lighttpd/conf-enabled -name '*.conf' -a ! -name 'letsencrypt.conf' -printf 'include \"%p\"\n' 2>/dev/null"
|
2015-10-17 19:04:49 +02:00
|
|
|
|
2015-10-17 19:11:03 +02:00
|
|
|
# If the URL starts with /admin, it is the Web interface
|
|
|
|
$HTTP["url"] =~ "^/admin/" {
|
2017-10-03 13:05:06 +02:00
|
|
|
# Create a response header for debugging using curl -I
|
2016-05-03 17:58:13 +02:00
|
|
|
setenv.add-response-header = (
|
|
|
|
"X-Pi-hole" => "The Pi-hole Web interface is working!",
|
|
|
|
"X-Frame-Options" => "DENY"
|
|
|
|
)
|
2018-10-26 20:12:11 +02:00
|
|
|
}
|
2017-02-21 20:36:59 +01:00
|
|
|
|
2018-10-26 20:12:11 +02:00
|
|
|
# Block . files from being served, such as .git, .github, .gitignore
|
|
|
|
$HTTP["url"] =~ "^/admin/\.(.*)" {
|
2020-05-19 10:09:51 +02:00
|
|
|
url.access-deny = ("")
|
2017-09-21 23:47:37 +02:00
|
|
|
}
|
|
|
|
|
2021-12-17 10:08:16 +01:00
|
|
|
# allow teleporter and API qr code iframe on settings page
|
|
|
|
$HTTP["url"] =~ "/(teleporter|api_token)\.php$" {
|
2021-12-10 07:17:13 +01:00
|
|
|
$HTTP["referer"] =~ "/admin/settings\.php" {
|
|
|
|
setenv.add-response-header = ( "X-Frame-Options" => "SAMEORIGIN" )
|
|
|
|
}
|
2021-12-10 07:09:42 +01:00
|
|
|
}
|
|
|
|
|
2020-05-19 10:09:51 +02:00
|
|
|
# Default expire header
|
|
|
|
expire.url = ( "" => "access plus 0 seconds" )
|