]> git.immae.eu Git - perso/Immae/Config/Nix.git/blobdiff - nixops/modules/websites/tools/dav/davical.nix
Cleanup php session directories
[perso/Immae/Config/Nix.git] / nixops / modules / websites / tools / dav / davical.nix
index 4e464ebfda106da940bfeaf1749795a8604728d5..89ba5683ce630b8649d9ca3c2fcf560e577bc6f5 100644 (file)
@@ -20,7 +20,7 @@ let
       destDir = "/run/keys/webapps";
       user = apache.user;
       group = apache.group;
-      permissions = "0700";
+      permissions = "0400";
       text = ''
         <?php
         $c->pg_connect[] = "dbname=${env.postgresql.database} user=${env.postgresql.user} host=${env.postgresql.socket} password=${env.postgresql.password}";
@@ -154,7 +154,7 @@ let
 
         ; Needed to avoid clashes in browser cookies (same domain)
         php_value[session.name] = DavicalPHPSESSID
-        php_admin_value[open_basedir] = "${basedir}:/tmp"
+        php_admin_value[open_basedir] = "${basedir}:/tmp:/var/lib/php/sessions/davical"
         php_admin_value[include_path] = "${awl}/inc:${webapp}/inc"
         php_admin_value[session.save_path] = "/var/lib/php/sessions/davical"
         php_flag[magic_quotes_gpc] = Off