4 ms·
mmm, blocking everything not http/2.0 is also blocking legit browser, while blocking http/1.0 does not block bots (at least not ChatGPT); blocking non-browsers
by kurren 2y ago
mmm, blocking everything not http/2.0 is also blocking legit browser, while blocking http/1.0 does not block bots (at least not ChatGPT); blocking non-browsers with $http_sec_fetch_mode works as expected.
- LinuxBender 2y agoDo you have a proxy in front of your site that is changing the protocol version? I have been using that on a dozen sites for years without issue. What browser are you using? Do your access logs show a HTTP/2.0 request? If you have something like Caddy or HAProxy in front of NGinx that is changing the proto version then you can create a similar rule at that outer layer. Or perhaps NGinx in front of NGinx doing a proxy pass?
- kurren 2y agoUsing Chrome on a mac, access logs say http 1.1 is accessing the domain. Nothing in front of Ngnix, but I'm wondering if I have the http 2 module on Nginx...
- LinuxBender 2y agoIt's probably compiled in but your config would look something like: server { listen 443 ssl backlog=1536 so_keepalive=58s:58s:5 deferred reuseport; http2 on; # [snip...] This is on nginx/1.26.2. Older versions looked a little different.