|
- <?xml version="1.0" encoding="UTF-8"?>
- <configuration>
- <system.webServer>
- <!--
- No hiddenSegments needed here: Framework/, Controllers/, tests/,
- tools/, docs/, and logs/ all live as siblings OUTSIDE this "public"
- folder, which is IIS's entire site physical path. There is no code
- path by which IIS could serve them, regardless of web.config -
- physical separation, not a filtering rule, is what protects them. See
- docs/ARCHITECTURE.md / docs/DECISIONS.md. The extension denylist below
- is kept only as cheap defense-in-depth against a stray file someday
- landing directly inside public/ by mistake.
- -->
- <security>
- <requestFiltering>
- <fileExtensions>
- <add fileExtension=".wsc" allowed="false" />
- <add fileExtension=".vbs" allowed="false" />
- <add fileExtension=".ps1" allowed="false" />
- <add fileExtension=".md" allowed="false" />
- </fileExtensions>
- </requestFiltering>
- </security>
- <!--
- No /self-test rewrite rule on this (production) site on purpose: the
- diagnostics endpoint is only exposed on the separate test-app/ site
- (see docs/ARCHITECTURE.md). Application.wsc's Run method still
- technically has a "/self-test" case - that's shared framework code,
- used by whichever site's web.config chooses to route to it - but
- nothing on this site's rewrite rules can ever reach it.
- -->
- <rewrite>
- <rules>
- <rule name="WscMvc-Hello" stopProcessing="true">
- <match url="^hello/?$" />
- <action type="Rewrite" url="Default.asp?route=/hello" appendQueryString="false" />
- </rule>
- </rules>
- </rewrite>
- <defaultDocument>
- <files>
- <clear />
- <add value="Default.asp" />
- </files>
- </defaultDocument>
- </system.webServer>
- </configuration>
|