#==================================================================== # Apache configuration for LemonLDAP::NG Portal #==================================================================== # To insert LLNG user id in Apache logs, declare this format and use it in # CustomLog directive #LogFormat "%v:%p %h %l %{Lm-Remote-User}o %t \"%r\" %>s %O %{Lm-Remote-Custom}o" llng # Portal Virtual Host (auth.__DNSDOMAIN__) ServerName auth.__DNSDOMAIN__ # See above to set LLNG user id in Apache logs #CustomLog __APACHELOGDIR__/portal.log llng # Uncomment this if you are running behind a reverse proxy and want # LemonLDAP::NG to see the real IP address of the end user # Adjust the settings to match the IP address of your reverse proxy # and the header containing the original IP address # #RemoteIPHeader X-Forwarded-For #RemoteIPInternalProxy 127.0.0.1 # DocumentRoot (FCGI scripts) DocumentRoot __PORTALSITEDIR__ Require all granted Options +ExecCGI +FollowSymLinks RewriteEngine On # For performances, you can put static html files: simply put the HTML # result (example: /oauth2/checksession.html) as static file. Then # uncomment the following line. # RewriteCond "%{REQUEST_URI}" "!\.html(?:/.*)?$" RewriteCond "%{REQUEST_URI}" "!^/(?:(?:static|javascript|favicon).*|.*\.fcgi(?:/.*)?)$" RewriteRule "^/(.+)$" "/index.fcgi/$1" [PT] # Uncomment this to mitigate memory leaks when using Perl 5.16 # FcgidMaxRequestsPerProcess 500 # Note that Content-Security-Policy header is generated by portal itself SetHandler fcgid-script # Authorization header needs to be passed when using Kerberos or OIDC = 2.4.13> CGIPassAuth On RewriteCond %{HTTP:Authorization} ^(.*) RewriteRule .* - [e=HTTP_AUTHORIZATION:%1] Options +ExecCGI header unset Lm-Remote-User # Uncomment this if status is enabled #FcgidInitialEnv LLNGSTATUSHOST 127.0.0.1:64321 # Static files Alias /static/ __PORTALSTATICDIR__ Require all granted Options +FollowSymLinks ExpiresActive On ExpiresDefault "access plus 1 month" DirectoryIndex index.fcgi index.html # REST/SOAP functions for sessions management (disabled by default) Require all denied # REST/SOAP functions for proxy auth and password reset (disabled by default) Require all denied # REST/SOAP functions for sessions access (disabled by default) Require all denied # REST/SOAP functions for configuration access (disabled by default) Require all denied # REST/SOAP functions for notification insertion (disabled by default) Require all denied # Enabe compression AddOutputFilterByType DEFLATE text/html text/plain text/xml text/javascript text/css SetOutputFilter DEFLATE BrowserMatch ^Mozilla/4 gzip-only-text/html BrowserMatch ^Mozilla/4\.0[678] no-gzip BrowserMatch \bMSIE !no-gzip !gzip-only-text/html SetEnvIfNoCase Request_URI \.(?:gif|jpe?g|png)$ no-gzip dont-vary Header append Vary User-Agent env=!dont-vary