Files
music_library/lib/music_library_web/endpoint.ex
T
2026-03-05 09:05:09 +00:00

87 lines
2.4 KiB
Elixir

defmodule MusicLibraryWeb.Endpoint do
use Phoenix.Endpoint, otp_app: :music_library
# The session will be stored in the cookie and signed,
# this means its contents can be read but not tampered with.
# Set :encryption_salt if you would also like to encrypt it.
@session_options [
store: :cookie,
key: "_music_library_key",
signing_salt: "esP44C0z",
same_site: "Strict",
# one week
max_age: 60 * 60 * 24 * 7,
sign: true,
encrypt: true
]
socket "/live", Phoenix.LiveView.Socket,
websocket: [connect_info: [session: @session_options]],
longpoll: [connect_info: [session: @session_options]]
# Serve at "/" the static files from "priv/static" directory.
#
# When code reloading is disabled (e.g., in production),
# the `gzip` option is enabled to serve compressed
# static files generated by running `phx.digest`.
plug Plug.Static,
at: "/",
from: :music_library,
gzip: not code_reloading?,
only: MusicLibraryWeb.static_paths()
if Code.ensure_loaded?(Tidewave) do
plug Tidewave
end
# Code reloading can be explicitly enabled under the
# :code_reloader configuration of your endpoint.
if code_reloading? do
socket "/phoenix/live_reload/socket", Phoenix.LiveReloader.Socket
plug Phoenix.LiveReloader
plug Phoenix.CodeReloader
plug Phoenix.Ecto.CheckRepoStatus, otp_app: :music_library
end
plug :reject_bot_scanners
plug Phoenix.LiveDashboard.RequestLogger,
param_key: "request_logger",
cookie_key: "request_logger"
plug Plug.RequestId
plug Plug.Telemetry, event_prefix: [:phoenix, :endpoint]
plug Plug.Parsers,
parsers: [:urlencoded, :multipart, :json],
pass: ["*/*"],
json_decoder: Phoenix.json_library()
plug Plug.MethodOverride
plug Plug.Head
plug Plug.Session, @session_options
plug MusicLibraryWeb.Router
defp reject_bot_scanners(%{request_path: "/wp-" <> _} = conn, _opts),
do: conn |> send_resp(404, "") |> halt()
defp reject_bot_scanners(%{request_path: "/wordpress" <> _} = conn, _opts),
do: conn |> send_resp(404, "") |> halt()
@blocked_paths [
"/.env",
"/grsiuk.php",
"/vgtyu.php",
"/xmlrpc.php",
"/vx.php",
"/xleet.php",
"/jq.php",
"/admin"
]
defp reject_bot_scanners(%{request_path: path} = conn, _opts) when path in @blocked_paths,
do: conn |> send_resp(404, "") |> halt()
defp reject_bot_scanners(conn, _opts), do: conn
end