Skip to content

Commit 0009cfb

Browse files
committed
fix(htaccess): serve .json and .ftl files statically instead of routing them to the front controller
The bundled pdf.js of files_pdfviewer loads its localization from apps/files_pdfviewer/js/pdfjs/web/locale/locale.json and apps/files_pdfviewer/js/pdfjs/web/locale/<lang>/viewer.ftl. With pretty URLs enabled, both extensions are missing from the static file exclusion of the generated front controller rule, so Apache passes the requests to index.php, which answers 404. pdf.js then fails to initialize and shows the alt text dialog instead of the document. Our nginx reference configuration serves both through try_files, and so does an Apache instance without pretty URLs, so this only brings the pretty URL case in line with the other two. To not widen what is reachable in the process, the package manager metadata that the nginx configuration explicitly returns 404 for is now denied in .htaccess as well. Resolves: #63512 Signed-off-by: Stefan - ByteSide.io <sr@byteside.io>
1 parent e8df656 commit 0009cfb

2 files changed

Lines changed: 11 additions & 1 deletion

File tree

‎.htaccess‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -140,6 +140,16 @@
140140

141141
RewriteRule ^(?:build|tests|config|lib|3rdparty|templates)/.* - [R=404,L]
142142

143+
##
144+
## Rule: Prevent access to package manager metadata and our shipped app list
145+
##
146+
## Context:
147+
## - Mirrors the equivalent `return 404` of our nginx reference configuration
148+
## - Required because `.json` is excluded from the front controller rule
149+
## generated by `lib/private/Setup.php`, so these would otherwise be served
150+
##
151+
RewriteRule ^(?:composer\.(?:json|lock)|package(?:-lock)?\.json|core/shipped\.json)$ - [R=404,L]
152+
143153
##
144154
## Rule: Maps most RFC 8615 compliant well-known URIs to our main frontend controller (/index.php) by default
145155
##

‎lib/private/Setup.php‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -614,7 +614,7 @@ public static function updateHtaccess(): bool {
614614
$content .= "\n Options -MultiViews";
615615
$content .= "\n RewriteRule ^core/js/oc.js$ index.php [PT,E=PATH_INFO:$1]";
616616
$content .= "\n RewriteRule ^core/preview.png$ index.php [PT,E=PATH_INFO:$1]";
617-
$content .= "\n RewriteCond %{REQUEST_FILENAME} !\\.(css|js|mjs|svg|gif|ico|jpg|jpeg|png|webp|html|otf|ttf|woff2?|map|webm|mp4|mp3|ogg|wav|flac|wasm|tflite)$";
617+
$content .= "\n RewriteCond %{REQUEST_FILENAME} !\\.(css|js|mjs|json|ftl|svg|gif|ico|jpg|jpeg|png|webp|html|otf|ttf|woff2?|map|webm|mp4|mp3|ogg|wav|flac|wasm|tflite)$";
618618
$content .= "\n RewriteCond %{REQUEST_FILENAME} !/core/ajax/update\\.php";
619619
$content .= "\n RewriteCond %{REQUEST_FILENAME} !/core/img/(favicon\\.ico|manifest\\.json)$";
620620
$content .= "\n RewriteCond %{REQUEST_FILENAME} !/(cron|public|remote|status)\\.php";

0 commit comments

Comments
 (0)