fix(openresty): disable server version disclosure in main config template

Add server_tokens off to the default OpenResty main config template, seeded
option template, and agent safe fallback config so responses no longer
expose nginx/OpenResty version numbers in Server headers or error pages.
This commit is contained in:
ryan
2026-06-21 14:25:32 +08:00
parent d3777eac2d
commit 40291136b7
4 changed files with 5 additions and 0 deletions
+1
View File
@@ -46,6 +46,7 @@ events {
http {
include mime.types;
default_type application/octet-stream;
server_tokens off;
{{OpenRestyConnectionUpgradeMap}}{{OpenRestyDefaultServerBlock}} log_format openflare_json escape=json '{"ts":"$time_iso8601","host":"$host","path":"$request_uri","remote_addr":"$remote_addr","status":$status,"request_time":$request_time,"bytes_sent":$body_bytes_sent,"request_length":$request_length}';
access_log {{OpenRestyAccessLogPath}} openflare_json;
sendfile on;