diff --git a/deployment/docker/nginx.conf b/deployment/docker/nginx.conf index e6e786dcb3..0ce88b6ce0 100644 --- a/deployment/docker/nginx.conf +++ b/deployment/docker/nginx.conf @@ -68,7 +68,14 @@ http { add_header Cache-Control "public"; } location / { - proxy_pass http://unix:/tmp/pretix.sock:/; + # Very important: + # proxy_pass http://unix:/tmp/pretix.sock:; + # is not the same as + # proxy_pass http://unix:/tmp/pretix.sock:/; + # In the latter case, nginx will apply its URL parsing, in the former it doesn't. + # There are situations in which pretix' API will deal with "file names" containing %2F%2F, which + # nginx will normalize to %2F, which can break ticket validation. + proxy_pass http://unix:/tmp/pretix.sock:; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header Host $http_host; } diff --git a/doc/admin/installation/docker_smallscale.rst b/doc/admin/installation/docker_smallscale.rst index acd402948b..b6c9585611 100644 --- a/doc/admin/installation/docker_smallscale.rst +++ b/doc/admin/installation/docker_smallscale.rst @@ -233,7 +233,7 @@ The following snippet is an example on how to configure a nginx proxy for pretix ssl_certificate_key /path/to/key.pem; location / { - proxy_pass http://localhost:8345/; + proxy_pass http://localhost:8345; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto https; proxy_set_header Host $http_host; diff --git a/doc/admin/installation/manual_smallscale.rst b/doc/admin/installation/manual_smallscale.rst index 6d692245f3..9e0c924d6a 100644 --- a/doc/admin/installation/manual_smallscale.rst +++ b/doc/admin/installation/manual_smallscale.rst @@ -237,7 +237,7 @@ The following snippet is an example on how to configure a nginx proxy for pretix add_header X-Content-Type-Options nosniff; location / { - proxy_pass http://localhost:8345/; + proxy_pass http://localhost:8345; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto https; proxy_set_header Host $http_host;