add 'do not modify' headers
[mirror/dsa-puppet.git] / modules / roles / files / debconf_wafer / wafertest.debconf.org
index 66e9b51..2415065 100644 (file)
@@ -1,11 +1,13 @@
+# do not modify - this file is maintained via puppet
+
 AddType application/font-woff2 .woff2
 
 Use common-debian-service-https-redirect * wafertest.debconf.org
 
 WSGIDaemonProcess wafertest \
   processes=3 threads=2 \
-  user=www-data group=www-data maximum-requests=750 umask=0007 display-name=wsgi-wafertest.debconf.org \
-  python-path=/srv/debconf-web/wafertest.debconf.org/dc18.dc.o/:/srv/debconf-web/wafertest.debconf.org/dc18.dc.o/ve/lib/python3.5/site-packages/
+  user=www-data group=debconf-web maximum-requests=750 umask=0007 display-name=wsgi-wafertest.debconf.org \
+  python-path=/srv/debconf-web/wafertest.debconf.org/dc19/:/srv/debconf-web/wafertest.debconf.org/dc19/ve/lib/python3.5/site-packages/
 
 <VirtualHost *:443>
   ServerAdmin admin@debconf.org
@@ -17,6 +19,7 @@ WSGIDaemonProcess wafertest \
   Use common-debian-service-ssl wafertest.debconf.org
   Use common-ssl-HSTS
 
+  Header always set Referrer-Policy "same-origin"
   Header always set X-Content-Type-Options nosniff
   Header always set X-XSS-Protection "1; mode=block"
 #  Header always set Access-Control-Allow-Origin: "*"
@@ -25,19 +28,20 @@ WSGIDaemonProcess wafertest \
   SSLCACertificateFile /var/lib/dsa/sso/ca.crt
   SSLCARevocationCheck chain
   SSLCARevocationFile /var/lib/dsa/sso/ca.crl
-  SSLVerifyClient optional
 
   WSGIProcessGroup wafertest
-  WSGIScriptAlias / /srv/debconf-web/wafertest.debconf.org/dc18.dc.o/wsgi.py
-  <Directory /srv/debconf-web/wafertest.debconf.org/dc18.dc.o>
+  WSGIScriptAlias / /srv/debconf-web/wafertest.debconf.org/dc19/wsgi.py
+  WSGIPassAuthorization On
+
+  <Directory /srv/debconf-web/wafertest.debconf.org/dc19>
     <Files wsgi.py>
       Require all granted
     </Files>
   </Directory>
 
-  Alias /static/ /srv/debconf-web/wafertest.debconf.org/dc18.dc.o/localstatic/
-  Alias /favicon.ico /srv/debconf-web/wafertest.debconf.org/dc18.dc.o/localstatic/img/favicon/favicon.ico
-  <Directory /srv/debconf-web/wafertest.debconf.org/dc18.dc.o/localstatic/>
+  Alias /static/ /srv/debconf-web/wafertest.debconf.org/dc19/localstatic/
+  Alias /favicon.ico /srv/debconf-web/wafertest.debconf.org/dc19/localstatic/img/favicon/favicon.ico
+  <Directory /srv/debconf-web/wafertest.debconf.org/dc19/localstatic/>
     Require all granted
 
     # A little hacky, but it means we won't accidentally catch non-hashed filenames
@@ -47,8 +51,8 @@ WSGIDaemonProcess wafertest \
     </FilesMatch>
   </Directory>
 
-  Alias /media/ /srv/debconf-web/wafertest.debconf.org/dc18.dc.o/media/
-  <Directory /srv/debconf-web/wafertest.debconf.org/dc18.dc.o/media/>
+  Alias /media/ /srv/debconf-web/wafertest.debconf.org/dc19/media/
+  <Directory /srv/debconf-web/wafertest.debconf.org/dc19/media/>
     Require all granted
   </Directory>