You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

51 lines
1.9KB

  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <configuration>
  3. <system.webServer>
  4. <!--
  5. No hiddenSegments needed here: Framework/, Controllers/, tests/,
  6. tools/, docs/, and logs/ all live as siblings OUTSIDE this "public"
  7. folder, which is IIS's entire site physical path. There is no code
  8. path by which IIS could serve them, regardless of web.config -
  9. physical separation, not a filtering rule, is what protects them. See
  10. docs/ARCHITECTURE.md / docs/DECISIONS.md. The extension denylist below
  11. is kept only as cheap defense-in-depth against a stray file someday
  12. landing directly inside public/ by mistake.
  13. -->
  14. <security>
  15. <requestFiltering>
  16. <fileExtensions>
  17. <add fileExtension=".wsc" allowed="false" />
  18. <add fileExtension=".vbs" allowed="false" />
  19. <add fileExtension=".ps1" allowed="false" />
  20. <add fileExtension=".md" allowed="false" />
  21. </fileExtensions>
  22. </requestFiltering>
  23. </security>
  24. <!--
  25. No /self-test rewrite rule on this production site: diagnostics are
  26. exposed only by the separate test app. Defense in depth lives in the
  27. bootstrap too: Default.asp always passes applicationName="production",
  28. so even a direct Default.asp?route=/self-test request is rejected by
  29. the shared framework route allowlist.
  30. -->
  31. <rewrite>
  32. <rules>
  33. <rule name="WscMvc-Root" stopProcessing="true">
  34. <match url="^$" />
  35. <action type="Rewrite" url="Default.asp?route=/hello" appendQueryString="false" />
  36. </rule>
  37. <rule name="WscMvc-Hello" stopProcessing="true">
  38. <match url="^hello/?$" />
  39. <action type="Rewrite" url="Default.asp?route=/hello" appendQueryString="false" />
  40. </rule>
  41. </rules>
  42. </rewrite>
  43. <defaultDocument>
  44. <files>
  45. <clear />
  46. <add value="Default.asp" />
  47. </files>
  48. </defaultDocument>
  49. </system.webServer>
  50. </configuration>

Powered by TurnKey Linux.