defmodule MusicLibraryWeb.Endpoint do use Phoenix.Endpoint, otp_app: :music_library # The session will be stored in the cookie and signed, # this means its contents can be read but not tampered with. # Set :encryption_salt if you would also like to encrypt it. @session_options [ store: :cookie, key: "_music_library_key", signing_salt: "esP44C0z", same_site: "Strict", # one week max_age: 60 * 60 * 24 * 7, sign: true, encrypt: true ] socket "/live", Phoenix.LiveView.Socket, websocket: [connect_info: [session: @session_options]], longpoll: [connect_info: [session: @session_options]] # Serve at "/" the static files from "priv/static" directory. # # When code reloading is disabled (e.g., in production), # the `gzip` option is enabled to serve compressed # static files generated by running `phx.digest`. plug Plug.Static, at: "/", from: :music_library, gzip: not code_reloading?, only: MusicLibraryWeb.static_paths() if Code.ensure_loaded?(Tidewave) do plug Tidewave end # Code reloading can be explicitly enabled under the # :code_reloader configuration of your endpoint. if code_reloading? do socket "/phoenix/live_reload/socket", Phoenix.LiveReloader.Socket plug Phoenix.LiveReloader plug Phoenix.CodeReloader plug Phoenix.Ecto.CheckRepoStatus, otp_app: :music_library end plug :reject_bot_scanners plug Phoenix.LiveDashboard.RequestLogger, param_key: "request_logger", cookie_key: "request_logger" plug Plug.RequestId plug Plug.Telemetry, event_prefix: [:phoenix, :endpoint] plug Plug.Parsers, parsers: [:urlencoded, :multipart, :json], pass: ["*/*"], json_decoder: Phoenix.json_library() plug Plug.MethodOverride plug Plug.Head plug Plug.Session, @session_options plug MusicLibraryWeb.Router defp reject_bot_scanners(%{request_path: "/wp-" <> _} = conn, _opts), do: conn |> send_resp(404, "") |> halt() defp reject_bot_scanners(%{request_path: "/wordpress" <> _} = conn, _opts), do: conn |> send_resp(404, "") |> halt() @blocked_paths [ "/.env", "/admin", "/blog/wp-includes/wlwmanifest.xml", "/files.php", "/grsiuk.php", "/jq.php", "/style.php", "/vgtyu.php", "/vx.php", "/xleet.php", "/xmlrpc.php" ] defp reject_bot_scanners(%{request_path: path} = conn, _opts) when path in @blocked_paths, do: conn |> send_resp(404, "") |> halt() defp reject_bot_scanners(conn, _opts), do: conn end