Onion site for wiki
This commit is contained in:
parent
cf57fd9cdd
commit
970038218f
107
src/freedombone
107
src/freedombone
|
@ -212,6 +212,7 @@ WIKI_DOMAIN_NAME=
|
||||||
WIKI_ADMIN_PASSWORD=
|
WIKI_ADMIN_PASSWORD=
|
||||||
WIKI_TITLE="${PROJECT_NAME} Wiki"
|
WIKI_TITLE="${PROJECT_NAME} Wiki"
|
||||||
WIKI_CODE=
|
WIKI_CODE=
|
||||||
|
WIKI_ONION_PORT=8089
|
||||||
|
|
||||||
# Domain name for your blog
|
# Domain name for your blog
|
||||||
FULLBLOG_DOMAIN_NAME=
|
FULLBLOG_DOMAIN_NAME=
|
||||||
|
@ -6939,6 +6940,87 @@ function install_wiki {
|
||||||
echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
echo '}' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
echo '}' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo 'server {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " listen 127.0.0.1:${WIKI_ONION_PORT} default_server;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " root /var/www/$WIKI_DOMAIN_NAME/htdocs;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " server_name $WIKI_DOMAIN_NAME;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' access_log off;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " error_log /var/log/nginx/${WIKI_DOMAIN_NAME}_error_ssl.log $WEBSERVER_LOG_LEVEL;" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' charset utf-8;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' client_max_body_size 20m;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' client_body_buffer_size 128k;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' limit_conn conn_limit_per_ip 10;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' limit_req zone=req_limit_per_ip burst=10 nodelay;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' add_header X-Frame-Options DENY;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' add_header X-Content-Type-Options nosniff;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' add_header Strict-Transport-Security "max-age=0;";' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # rewrite to front controller as default rule' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location / {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' rewrite ^/(.*) /index.php?q=$uri&$args last;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " # make sure webfinger and other well known services aren't blocked" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # by denying dot files and rewrite request to the front controller' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location ^~ /.well-known/ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' allow all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # statically serve these file types when possible' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # otherwise fall back to front controller' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # allow browser to cache them' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # added .htm for advanced source code editor library' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location ~* \.(jpg|jpeg|gif|png|ico|css|js|htm|html|ttf|woff|svg)$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' expires 30d;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' try_files $uri /index.php?q=$uri&$args;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # block these file types' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location ~* \.(tpl|md|tgz|log|out)$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # pass the PHP scripts to FastCGI server listening on 127.0.0.1:9000' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # or a unix socket' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location ~* \.php$ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # Zero-day exploit defense.' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # http://forum.nginx.org/read.php?2,88845,page=3' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " # Won't work properly (404 error) if the file is not stored on this" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " # server, which is entirely possible with php-fpm/php-fcgi." >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " # Comment the 'try_files' line out if you set up php-fpm/php-fcgi on" >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo " # another machine. And then cross your fingers that you won't get hacked." >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' try_files $uri $uri/ /index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # NOTE: You should have "cgi.fix_pathinfo = 0;" in php.ini' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' fastcgi_split_path_info ^(.+\.php)(/.+)$;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # With php5-cgi alone:' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # fastcgi_pass 127.0.0.1:9000;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # With php5-fpm:' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' fastcgi_pass unix:/var/run/php5-fpm.sock;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' include fastcgi_params;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' fastcgi_index index.php;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' # deny access to all dot files' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location ~ /\. {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' #deny access to store' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location ~ /store {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location ~ /(data|conf|bin|inc)/ {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' location ~ /\.ht {' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' deny all;' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo ' }' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
echo '}' >> /etc/nginx/sites-available/$WIKI_DOMAIN_NAME
|
||||||
|
|
||||||
if [ ! -f /etc/ssl/certs/$WIKI_DOMAIN_NAME.dhparam ]; then
|
if [ ! -f /etc/ssl/certs/$WIKI_DOMAIN_NAME.dhparam ]; then
|
||||||
if [[ $LETSENCRYPT_ENABLED != "yes" ]]; then
|
if [[ $LETSENCRYPT_ENABLED != "yes" ]]; then
|
||||||
|
@ -6952,8 +7034,27 @@ function install_wiki {
|
||||||
configure_php
|
configure_php
|
||||||
|
|
||||||
nginx_ensite $WIKI_DOMAIN_NAME
|
nginx_ensite $WIKI_DOMAIN_NAME
|
||||||
service php5-fpm restart
|
|
||||||
service nginx restart
|
if [ ! -d /var/lib/tor ]; then
|
||||||
|
echo $'No Tor installation found. Wiki onion site cannot be configured.'
|
||||||
|
exit 877367
|
||||||
|
fi
|
||||||
|
if ! grep -q "hidden_service_wiki" /etc/tor/torrc; then
|
||||||
|
echo 'HiddenServiceDir /var/lib/tor/hidden_service_wiki/' >> /etc/tor/torrc
|
||||||
|
echo "HiddenServicePort 80 127.0.0.1:${WIKI_ONION_PORT}" >> /etc/tor/torrc
|
||||||
|
echo $'Added onion site for Wiki'
|
||||||
|
fi
|
||||||
|
|
||||||
|
systemctl restart php5-fpm
|
||||||
|
systemctl restart nginx
|
||||||
|
systemctl restart tor
|
||||||
|
|
||||||
|
if [ ! -f /var/lib/tor/hidden_service_wiki/hostname ]; then
|
||||||
|
echo $'Wiki onion site hostname not found'
|
||||||
|
exit 52383
|
||||||
|
fi
|
||||||
|
WIKI_ONION_HOSTNAME=$(cat /var/lib/tor/hidden_service_wiki/hostname)
|
||||||
|
echo "Wiki onion domain:${WIKI_ONION_HOSTNAME}" >> $COMPLETION_FILE
|
||||||
|
|
||||||
# update the dynamic DNS
|
# update the dynamic DNS
|
||||||
CURRENT_DDNS_DOMAIN=$WIKI_DOMAIN_NAME
|
CURRENT_DDNS_DOMAIN=$WIKI_DOMAIN_NAME
|
||||||
|
@ -6965,12 +7066,14 @@ function install_wiki {
|
||||||
echo '' >> /home/$MY_USERNAME/README
|
echo '' >> /home/$MY_USERNAME/README
|
||||||
echo $'Wiki' >> /home/$MY_USERNAME/README
|
echo $'Wiki' >> /home/$MY_USERNAME/README
|
||||||
echo '====' >> /home/$MY_USERNAME/README
|
echo '====' >> /home/$MY_USERNAME/README
|
||||||
|
echo $"Wiki onion domain: ${WIKI_ONION_HOSTNAME}" >> /home/$MY_USERNAME/README
|
||||||
echo $"Wiki username: $MY_USERNAME" >> /home/$MY_USERNAME/README
|
echo $"Wiki username: $MY_USERNAME" >> /home/$MY_USERNAME/README
|
||||||
echo $"Wiki password: $WIKI_ADMIN_PASSWORD" >> /home/$MY_USERNAME/README
|
echo $"Wiki password: $WIKI_ADMIN_PASSWORD" >> /home/$MY_USERNAME/README
|
||||||
echo '' >> /home/$MY_USERNAME/README
|
echo '' >> /home/$MY_USERNAME/README
|
||||||
echo $'Once you have set up the wiki then remove the install file:' >> /home/$MY_USERNAME/README
|
echo $'Once you have set up the wiki then remove the install file:' >> /home/$MY_USERNAME/README
|
||||||
echo '' >> /home/$MY_USERNAME/README
|
echo '' >> /home/$MY_USERNAME/README
|
||||||
echo " rm /var/www/$WIKI_DOMAIN_NAME/htdocs/install.php" >> /home/$MY_USERNAME/README
|
echo " rm /var/www/$WIKI_DOMAIN_NAME/htdocs/install.php" >> /home/$MY_USERNAME/README
|
||||||
|
echo '' >> /home/$MY_USERNAME/README
|
||||||
chown $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/README
|
chown $MY_USERNAME:$MY_USERNAME /home/$MY_USERNAME/README
|
||||||
chmod 600 /home/$MY_USERNAME/README
|
chmod 600 /home/$MY_USERNAME/README
|
||||||
fi
|
fi
|
||||||
|
|
Loading…
Reference in New Issue