+If you are using nginx, you can add the following to your $vhost.conf:
+
+```nginx
+location ~ /var-.* {
+ deny all;
+ return 404;
+}
+```
+
You should also remove un-necessessary write access once the installation is done (ex: configuration file).
An other obvious basic security is to let access users to the site by HTTPS.
You should also remove un-necessessary write access once the installation is done (ex: configuration file).
An other obvious basic security is to let access users to the site by HTTPS.
@@ -168,6+177,18 @@ Simply go to ```/script.php``` with your web browser.
Be sure your PHP installation is not using safe mode, it may cause timeouts.
Be sure your PHP installation is not using safe mode, it may cause timeouts.
+If you're using nginx, you might need to increase `client_max_body_size` or remove the restriction altogether. In your nginx.conf:
+
+```nginx
+http {
+ # disable max upload size
+ client_max_body_size 0;
+ # add timeouts for very large uploads
+ client_header_timeout 30m;
+ client_body_timeout 30m;
+}
+```
+
### How can I monitor the use of my Jirafeau instance?
You may use Munin and simple scripts to collect the number of files in the Jirafeau instance as well as the disk space occupied by all the files. You can consult this [web page](https://blog.bandinelli.net/index.php?post/2016/05/15/Scripts-Munin-pour-Jirafeau).
### How can I monitor the use of my Jirafeau instance?
You may use Munin and simple scripts to collect the number of files in the Jirafeau instance as well as the disk space occupied by all the files. You can consult this [web page](https://blog.bandinelli.net/index.php?post/2016/05/15/Scripts-Munin-pour-Jirafeau).