diff --git a/.gitignore b/.gitignore index 392dac0..0dd9cd9 100644 --- a/.gitignore +++ b/.gitignore @@ -13,4 +13,8 @@ /config/security.yaml /config/security-private.php /config/versions.yaml +# Per-host env override tree — holds LIVE secrets (JWT, CSRF salt, git-sync +# token) + per-host overrides. Never commit/sync: git-sync stages anything +# not gitignored, so an untracked /env/ would boomerang to Gitea. +/env/ /themes/intotheeast/node_modules/ diff --git a/config/plugins/api.yaml b/config/plugins/api.yaml index e3b1e18..8a89c21 100644 --- a/config/plugins/api.yaml +++ b/config/plugins/api.yaml @@ -49,7 +49,8 @@ invitations: popularity: enabled: true exclude_admin: true - exclude_ips: { } + exclude_ips: + - 83.135.64.30 history: daily: 30 monthly: 12 diff --git a/env/intotheeast.com/config/plugins/api-private.php b/env/intotheeast.com/config/plugins/api-private.php deleted file mode 100644 index 1e07a37..0000000 --- a/env/intotheeast.com/config/plugins/api-private.php +++ /dev/null @@ -1,7 +0,0 @@ -$z>\%+G''Jo' -branch: main -logging: false -password: gitsync-def502005b5427cc6afd28ea66682788711e72b3e31bcb6bd302db4232e48a8783900ed76bf2cf891b3e4545dd925a5f5276fa683bf033797b5c6074f7ef0c520c455e34e27392be46615378e779cba61fe4a7f710fcbf157fb9709142794bce7d785e3738de84dd6887e0287f2923e96ae12ce446e4e61285a3ce48 -sync: - direction: both - on_save: true - on_delete: true - on_media: true - cron_enable: false - cron_at: '0 12,23 * * *' -remote: - name: origin - branch: main -git: - author: gituser - message: '(Grav GitSync) Automatic Commit' - name: GitSync - email: mischa@gorinskat.nl - bin: git - ignore: '' - private_key: '' diff --git a/env/intotheeast.com/config/security-private.php b/env/intotheeast.com/config/security-private.php deleted file mode 100644 index d185898..0000000 --- a/env/intotheeast.com/config/security-private.php +++ /dev/null @@ -1,7 +0,0 @@ -/user/env//config/system.yaml -# and Grav's `environment://config` stream (keyed on the request hostname) -# layers it on top of `user://config`. -# -# These values are deliberately NOT in the committed system.yaml because they -# would break local development (see CLAUDE.md §1 — dev keeps twig.cache:false -# so theme edits take effect immediately). Prod is the only place they apply. -# -# Deploy with: make remote-apply-env-prod -# The user/env/ tree is outside the content repo's tracked folders, so it is -# NOT restored by content-push / git-sync / remote-fetch-content — re-run the -# target above after any fresh install. -twig: - cache: true - debug: false - auto_reload: false - -# Compression / connection handling. -# -# This host is not FastCGI (no fastcgi_finish_request()), so Grav's shutdown -# "early connection close" falls back to emitting `Content-Encoding: identity` -# to ask the webserver not to compress. But Apache's mod_deflate compresses -# anyway and adds `Content-Encoding: gzip`, giving TWO conflicting headers — -# the browser can't decode the body and renders raw gzip bytes (a garbage -# page). Note: allow_webserver_gzip:true takes the SAME identity branch, so it -# does not help. The real fix is to disable the early-close path, so Grav never -# emits the bogus header and mod_deflate compresses cleanly (single header). -debugger: - shutdown: - close_connection: false -# Let the webserver own gzip; Grav does not compress or double-label. -cache: - gzip: false - allow_webserver_gzip: false