diff --git a/README.md b/README.md index cf25113..b38c9e8 100644 --- a/README.md +++ b/README.md @@ -63,6 +63,9 @@ The following examples assume that the reverse proxy runs on the Docker host. Replace `hub.example.com` with the public frontend domain. Keep `FRONTEND_BIND=127.0.0.1:18080` in the frontend `.env`. The examples also assume that Drivers Hub: Backend listens on `127.0.0.1:17777` and uses the `/api` prefix. +They do not publish the API documentation or the upstream service restart +endpoint. The restart endpoint does not manage a Docker container. All other +API routes remain available to the frontend and configured external services. ### Standalone Nginx @@ -85,7 +88,13 @@ server { ssl_certificate /etc/letsencrypt/live/hub.example.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/hub.example.com/privkey.pem; - location ^~ /api/ { + # Do not publish API schemas or interactive API documentation. + # The upstream restart endpoint cannot restart this Docker container. + location ~ ^/api/(?:docs?(?:/|$)|redoc/?$|openapi\.json$|restart$) { + return 404; + } + + location /api/ { proxy_pass http://127.0.0.1:17777; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; @@ -119,6 +128,13 @@ Add this site block to the Caddyfile: ```caddyfile hub.example.com { + # Do not publish API schemas or interactive API documentation. + # The upstream restart endpoint cannot restart this Docker container. + @blocked path /api/openapi.json /api/doc /api/doc/* /api/docs /api/docs/* /api/redoc /api/restart + handle @blocked { + respond 404 + } + handle /api/* { reverse_proxy 127.0.0.1:17777 } @@ -151,7 +167,13 @@ Use a domain or subdomain that has a valid TLS certificate in Plesk. 5. Add this block to **Additional nginx directives**: ```nginx -location ^~ /api/ { +# Do not publish API schemas or interactive API documentation. +# The upstream restart endpoint cannot restart this Docker container. +location ~ ^/api/(?:docs?(?:/|$)|redoc/?$|openapi\.json$|restart$) { + return 404; +} + +location /api/ { proxy_pass http://127.0.0.1:17777; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr;