mirror of
https://github.com/Dispatcharr/Dispatcharr.git
synced 2026-07-22 17:48:09 +00:00
This update modifies permission classes in multiple viewsets to restrict access based on user roles. The `IsAdmin` permission is now enforced for several actions, including group management and permission listing, ensuring that only administrators can perform sensitive operations. Additionally, a new utility function, `resolve_safe_local_data_path`, is introduced to enhance security when accessing local file paths. The changes improve overall security and maintainability of the codebase.
97 lines
2.8 KiB
Nginx Configuration File
97 lines
2.8 KiB
Nginx Configuration File
proxy_cache_path /data/logo_cache levels=1:2 keys_zone=logo_cache:10m
|
|
inactive=24h use_temp_path=off;
|
|
|
|
server {
|
|
listen NGINX_PORT;
|
|
listen [::]:NGINX_PORT;
|
|
|
|
proxy_connect_timeout 75;
|
|
proxy_send_timeout 300;
|
|
proxy_read_timeout 300;
|
|
client_max_body_size 0;
|
|
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Host $host:$server_port;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-Port $server_port;
|
|
|
|
# Serve Django via uWSGI
|
|
location / {
|
|
include uwsgi_params;
|
|
uwsgi_pass unix:/app/uwsgi.sock;
|
|
}
|
|
|
|
location /assets/ {
|
|
root /app/static;
|
|
}
|
|
|
|
location /static/ {
|
|
root /app;
|
|
}
|
|
|
|
location /logos/ {
|
|
root /data;
|
|
}
|
|
|
|
# Internal location for X-Accel-Redirect backup downloads
|
|
# Django handles auth, nginx serves the file directly
|
|
location /protected-backups/ {
|
|
internal;
|
|
alias /data/backups/;
|
|
}
|
|
|
|
location ~ ^/api/channels/logos/(?<logo_id>\d+)/cache/ {
|
|
proxy_pass http://127.0.0.1:5656;
|
|
proxy_cache logo_cache;
|
|
proxy_cache_key "$scheme$request_uri"; # Cache per logo URL
|
|
proxy_cache_valid 200 24h; # Cache for 24 hours
|
|
proxy_cache_use_stale error timeout updating; # Serve stale if Django is slow
|
|
}
|
|
|
|
location ~ ^/api/vod/vodlogos/(?<logo_id>\d+)/cache/ {
|
|
proxy_pass http://127.0.0.1:5656;
|
|
proxy_cache logo_cache;
|
|
proxy_cache_key "$scheme$request_uri"; # Cache per logo URL
|
|
proxy_cache_valid 200 24h; # Cache for 24 hours
|
|
proxy_cache_use_stale error timeout updating; # Serve stale if Django is slow
|
|
}
|
|
|
|
location ~ ^/api/epg/programs/(?<prog_id>\d+)/poster/ {
|
|
proxy_pass http://127.0.0.1:5656;
|
|
proxy_cache logo_cache;
|
|
proxy_cache_key "$scheme$request_uri";
|
|
proxy_cache_valid 200 24h;
|
|
proxy_cache_use_stale error timeout updating;
|
|
}
|
|
|
|
# admin disabled when not in dev mode
|
|
location ~ ^/admin/?$ {
|
|
return 301 /login;
|
|
}
|
|
|
|
# Route HDHR request to Django
|
|
location /hdhr {
|
|
include uwsgi_params;
|
|
uwsgi_pass unix:/app/uwsgi.sock;
|
|
}
|
|
|
|
# WebSockets for real-time communication
|
|
location /ws/ {
|
|
proxy_pass http://127.0.0.1:8001;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
proxy_set_header Connection "Upgrade";
|
|
}
|
|
|
|
# Route TS proxy requests to the dedicated instance
|
|
location /proxy/ {
|
|
include uwsgi_params;
|
|
uwsgi_pass unix:/app/uwsgi.sock;
|
|
uwsgi_buffering off;
|
|
uwsgi_read_timeout 300s;
|
|
uwsgi_send_timeout 300s;
|
|
client_max_body_size 0;
|
|
}
|
|
}
|