diff --git a/.devcontainer/images/nginx/conf/nginx_external_endpoints.conf b/.devcontainer/images/nginx/conf/nginx_external_endpoints.conf index 4744b1e52c5..cafd1cae562 100644 --- a/.devcontainer/images/nginx/conf/nginx_external_endpoints.conf +++ b/.devcontainer/images/nginx/conf/nginx_external_endpoints.conf @@ -1,12 +1,7 @@ server { listen 80; - # Forbid access to internal endpoints - location /internal/v4/ { - return 403 'Forbidden'; - } - - # proxy and log all CC traffic + # proxy and log all CC traffic (including internal endpoints) location / { access_log /tmp/nginx-access.log main; proxy_buffering off; @@ -60,54 +55,11 @@ server { include public_upload.conf; } - location ~ /staging/(v3/)?(droplets|buildpack_cache)/.*/upload { - # Allow download the droplets and buildpacks - if ($request_method = GET){ - proxy_pass http://cloud_controller; - } - - # Allow large uploads - client_max_body_size 1536M; #already enforced upstream/but doesn't hurt. - - # Pass along auth header - set $auth_header $upstream_http_x_auth; - proxy_set_header Authorization $auth_header; - - # Pass altered request body to this location - upload_pass @cc_uploads; - - # Store files to this directory - upload_store /tmp/staged_droplet_uploads; - - # Allow uploaded files to be read only by user - #upload_store_access user:r; - - # Set specified fields in request body - upload_set_form_field "droplet_path" $upload_tmp_path; - - #on any error, delete uploaded files. - upload_cleanup 400-505; - } - # Pass altered request body to a backend location @cc_uploads { proxy_pass http://cloud_controller; } - location ~ ^/internal_redirect/(.*){ - # only allow internal redirects - internal; - - set $download_url $1; - - #have to manualy pass along auth header - set $auth_header $upstream_http_x_auth; - proxy_set_header Authorization $auth_header; - - # Download the file and send it to client - proxy_pass $download_url; - } - location /nginx_status { stub_status on;