summaryrefslogtreecommitdiff
path: root/hostnix/elmo/web.nix
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-15 16:52:42 -0400
committerJoe Mou <dev@mou.fo>2025-04-16 00:13:55 -0400
commitae381a3ddecfcf28284be2afa009adbab4ca934f (patch)
tree3197b6a494ada2df819261e5b972e3292e094803 /hostnix/elmo/web.nix
parent61779313cfdf8556daf3a460a7781da432c0bbc3 (diff)
Use ACLs to grant user access to /src/syncthing
Diffstat (limited to 'hostnix/elmo/web.nix')
-rw-r--r--hostnix/elmo/web.nix5
1 files changed, 1 insertions, 4 deletions
diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix
index e63d336..09aa588 100644
--- a/hostnix/elmo/web.nix
+++ b/hostnix/elmo/web.nix
@@ -3,12 +3,9 @@
# TODO serve /srv behind authentication
{
+ # Assumes proper permissions set by syncthing.nix
systemd.tmpfiles.rules = [
"L /home/joe/Public - - - - /srv/syncthing/Public/"
- # It's quite hard to allow granular access to nginx using classic UNIX
- # permissions, so use ACLs instead.
- "A+ /srv/syncthing - - - - d:u:nginx:rX"
- "A+ /srv/syncthing - - - - u:nginx:rX"
];
services.nginx = {