diff --git a/caddy/frankenphp/Caddyfile b/caddy/frankenphp/Caddyfile index 10d56e246b..cc9bd523fe 100644 --- a/caddy/frankenphp/Caddyfile +++ b/caddy/frankenphp/Caddyfile @@ -26,7 +26,9 @@ #} root {$SERVER_ROOT:public/} - encode zstd br gzip + # Compressed SSE streams cost memory per subscriber and enable BREACH-style attacks. + @compressible not path /.well-known/mercure + encode @compressible zstd br gzip # Uncomment the following lines to enable Mercure and Vulcain modules #mercure { diff --git a/docs/mercure.md b/docs/mercure.md index 8ecb84929c..4a692ecd81 100644 --- a/docs/mercure.md +++ b/docs/mercure.md @@ -50,6 +50,14 @@ Access tokens must carry the identifier of the `issuer` they were signed by in t > > Uncomment the Mercure section in `/etc/frankenphp/Caddyfile` to enable it. +If you enable compression with the `encode` directive, exclude the hub from it: +compressed SSE streams cost memory per subscriber and enable BREACH-style attacks. + +```caddyfile +@compressible not path /.well-known/mercure +encode @compressible zstd br gzip +``` + ### With `php-server` `frankenphp php-server --mercure` starts the hub without a `Caddyfile`, configured by environment variables: