summaryrefslogtreecommitdiff
path: root/hostnix/elmo/web.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/web.nix')
-rw-r--r--hostnix/elmo/web.nix5
1 files changed, 1 insertions, 4 deletions
diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix
index e63d336..09aa588 100644
--- a/hostnix/elmo/web.nix
+++ b/hostnix/elmo/web.nix
@@ -3,12 +3,9 @@
# TODO serve /srv behind authentication
{
+ # Assumes proper permissions set by syncthing.nix
systemd.tmpfiles.rules = [
"L /home/joe/Public - - - - /srv/syncthing/Public/"
- # It's quite hard to allow granular access to nginx using classic UNIX
- # permissions, so use ACLs instead.
- "A+ /srv/syncthing - - - - d:u:nginx:rX"
- "A+ /srv/syncthing - - - - u:nginx:rX"
];
services.nginx = {