From ae381a3ddecfcf28284be2afa009adbab4ca934f Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 15 Apr 2025 16:52:42 -0400 Subject: Use ACLs to grant user access to /src/syncthing --- hostnix/elmo/web.nix | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) (limited to 'hostnix/elmo/web.nix') diff --git a/hostnix/elmo/web.nix b/hostnix/elmo/web.nix index e63d336..09aa588 100644 --- a/hostnix/elmo/web.nix +++ b/hostnix/elmo/web.nix @@ -3,12 +3,9 @@ # TODO serve /srv behind authentication { + # Assumes proper permissions set by syncthing.nix systemd.tmpfiles.rules = [ "L /home/joe/Public - - - - /srv/syncthing/Public/" - # It's quite hard to allow granular access to nginx using classic UNIX - # permissions, so use ACLs instead. - "A+ /srv/syncthing - - - - d:u:nginx:rX" - "A+ /srv/syncthing - - - - u:nginx:rX" ]; services.nginx = { -- cgit v1.3.1