diff --git a/.docker/nginx/conf.d/default.conf b/.docker/nginx/conf.d/default.conf index c225ccc..e5cff82 100644 --- a/.docker/nginx/conf.d/default.conf +++ b/.docker/nginx/conf.d/default.conf @@ -25,6 +25,9 @@ server { location ~* ^/wp-content/uploads/.*\.php$ { deny all; } + location ~* ^/wp-content/.*/vendor(-bin)?/.*\.php$ { + deny all; + } location ~ \.php$ { try_files $uri =404; fastcgi_split_path_info ^(.+\.php)(/.+)$; diff --git a/tests/security/helpers/nginx.bash b/tests/security/helpers/nginx.bash index 845e434..4dbebaf 100644 --- a/tests/security/helpers/nginx.bash +++ b/tests/security/helpers/nginx.bash @@ -85,6 +85,15 @@ nginx_hardening_integration_setup() { php:8.3-fpm)" } +nginx_hardening_document_root_file() { + local path="$1" + local content="$2" + local file="${nginx_hardening_tmp}/document-root/${path}" + + mkdir -p "$(dirname "${file}")" + printf '%s\n' "${content}" > "${file}" +} + nginx_hardening_integration_start() { local value="${1-__UNSET__}" local -a environment_args=() diff --git a/tests/security/vendor-php.bats b/tests/security/vendor-php.bats new file mode 100644 index 0000000..64a4b54 --- /dev/null +++ b/tests/security/vendor-php.bats @@ -0,0 +1,66 @@ +#!/usr/bin/env bats + +load 'helpers/nginx.bash' + +setup() { + nginx_hardening_integration_setup + nginx_hardening_document_root_file wp-content/themes/theme/vendor/wordpress/wp-admin/setup-config.php '