commit c9d5fdc5c70091c88134536435553bb5a0f3743f
parent 64ae10dec8673c8b41f18be36ec8043a130b7c66
Author: Thien-Thi Nguyen <ttn@gnuvola.org>
Date: Wed, 11 Aug 2021 07:19:46 -0400
replace apache FIXME w/ config frag + blurb
https://docs.trafficserver.apache.org/en/latest/admin-guide/plugins/header_rewrite.en.html
Diffstat:
1 file changed, 8 insertions(+), 1 deletion(-)
diff --git a/taler-merchant-manual.rst b/taler-merchant-manual.rst
@@ -959,7 +959,14 @@ Note that the above again assumes your domain name is ``example.com`` and that
you have TLS configured. Note that you must add the ``https`` header unless
your site is not available via TLS.
-FIXME: What about 40[34] swizzling? (#6944)
+For higher security (by leaking less information), you can add to the configuration:
+
+.. code-block:: apacheconf
+
+ cond %{STATUS} =404
+ set-status 403
+
+This remaps all 404 response codes (Unavailable) to 403 (Forbidden).
The above configuration(s) are both incomplete. You must still additionally
set up access control!