Assets Directory Block

A CORS, MIME and Download Block for an Assets Directory

Fonts and JSON fetched by sister sites need CORS headers (Security Headers and CORS), and nothing uploaded to /assets/ may run:

/var/www/example/assets/.htaccess for files shared with sister sitesApache config
# Needs: mod_setenvif, mod_headers, mod_mime; AllowOverride FileInfo
AddType application/json .map
AddCharset utf-8 .css .js .mjs .json .map .svg
SetEnvIf Origin "^(https://(www|shop|blog)\.example\.com)$" CORS_ORIGIN=$1
Header set Access-Control-Allow-Origin "%{CORS_ORIGIN}e" env=CORS_ORIGIN
Header merge Vary "Origin"
<FilesMatch "\.(pdf|zip|csv|xlsx)$">
  Header set Content-Disposition "attachment"
</FilesMatch>
<FilesMatch "\.(php\d?|phtml|phar|pl|py|cgi|sh)$">
  SetHandler default-handler
  ForceType text/plain
</FilesMatch>

Line 2 fills a gap in Ubuntu 225 's mime.types (MIME Types). The header takes one origin, not a list, so lines 4 and 5 echo an allowed one back; line 6 warns caches. Lines 7 to 9 save files under their real type, and lines 10 to 13 send scripts as text:

Output of 82
/assets/fonts/inter.woff2  shop  font/woff2        ACAO: https://shop.example.com Vary: Origin
/assets/fonts/inter.woff2  evil  font/woff2        Vary: Origin
/assets/app.js.map         -     application/json; charset=utf-8 Vary: Origin
/assets/files/prices.pdf   -     application/pdf   Vary: Origin CD: attachment
/assets/files/shell.php    -     text/plain        body: <?php echo "ran";