From c95cc321220bc52084be7813910afb7bce78dd89 Mon Sep 17 00:00:00 2001 From: Dorian Niemiec Date: Tue, 10 Sep 2024 19:36:05 +0200 Subject: [PATCH] docs: add a security recommendation to notes for Next.js integration mod --- source/mods.md | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/source/mods.md b/source/mods.md index eb8b81f..6e62123 100644 --- a/source/mods.md +++ b/source/mods.md @@ -107,6 +107,24 @@ _View the [change log.](/greenrhombus-changelog)_ The webroot (_wwwroot_ _config.json_ property) serves as a Next.js application directory. It's recommended to set the owner of the Next.js application directory (around with all the files in it) as the user, on which SVR.JS is running (usually "svrjs"). Setting a `NODE_ENV` environment variable to `development` in SVR.JS configuration enables Next.js development server. +It's also recommended to forbid the access to ".env" file and ".git" directories, in case Next.js integration mod fails to load. You can set up _nonStandardCodes_ _config.json_ property like this: +```json +{ + "nonStandardCodes": [ + { + "scode": 403, + "regex": "/^\\/\\.env(?:\\.local)?(?:$|[#?])/" + }, + { + "scode": 403, + "regex": "/^\\/\\.git/" + }, + ...other non-standard codes... + ], + ...other config.json properties... +} +``` + _View the [change log.](/nextjs-integration-changelog)_ ### OrangeCircle