Skip to content

Commit 63b75aa

Browse files
authored
Merge pull request #1443 from anarcat/mode-fix
use more restrictive mode on temp paths
2 parents 66b86dc + 1007d02 commit 63b75aa

File tree

2 files changed

+6
-4
lines changed

2 files changed

+6
-4
lines changed

manifests/config.pp

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -209,13 +209,15 @@
209209
file { $client_body_temp_path:
210210
ensure => directory,
211211
owner => $daemon_user,
212+
mode => '0700',
212213
}
213214
}
214215

215216
if $proxy_temp_path {
216217
file { $proxy_temp_path:
217218
ensure => directory,
218219
owner => $daemon_user,
220+
mode => '0700',
219221
}
220222
}
221223

spec/classes/nginx_spec.rb

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -325,13 +325,13 @@
325325
is_expected.to contain_file('/run/nginx/client_body_temp').with(
326326
ensure: 'directory',
327327
group: 'root',
328-
mode: '0644'
328+
mode: '0700'
329329
)
330330
else
331331
is_expected.to contain_file('/var/nginx/client_body_temp').with(
332332
ensure: 'directory',
333333
group: 'root',
334-
mode: '0644'
334+
mode: '0700'
335335
)
336336
end
337337
end
@@ -341,13 +341,13 @@
341341
is_expected.to contain_file('/run/nginx/proxy_temp').with(
342342
ensure: 'directory',
343343
group: 'root',
344-
mode: '0644'
344+
mode: '0700'
345345
)
346346
else
347347
is_expected.to contain_file('/var/nginx/proxy_temp').with(
348348
ensure: 'directory',
349349
group: 'root',
350-
mode: '0644'
350+
mode: '0700'
351351
)
352352
end
353353
end

0 commit comments

Comments
 (0)