MediaWiki§
To run the MediaWiki collaboration and documentation platform using Unit:
Install Unit with a PHP language module.
Install MediaWiki’s core files. Here, we install it at /path/to/app/; use a real path in your configuration.
Run the following command (as root) so Unit can access the application directory:
# chown -R unit:unit /path/to/app/
Note
The unit:unit user-group pair is available only with official packages, Docker images, and some third-party repos. Otherwise, account names may differ; run the ps aux | grep unitd command to be sure.
For further details, including permissions, see the security checklist.
Next, prepare the MediaWiki configuration for Unit (use real values for share and root):
Warning
The share action in the configuration below serves any file that no earlier step sends elsewhere. It serves a PHP file as source; it never runs it. The uri patterns are globs and match case-sensitively, so *.php does not match /config.PHP. On a case-insensitive filesystem (macOS, Windows, or a Docker Desktop bind mount from either) that file exists, and the share returns it with the passwords in it. A file the patterns never name, such as config.php.bak or settings.inc, is served the same way.
Add a types allow-list to the share action. Keep the fallback where the configuration has one:
"types": ["image/*", "text/css", "application/javascript", "font/*"]
Unit compares this list with the MIME type it looks up from the file’s extension. The lookup is case-insensitive, so /config.PHP still resolves to application/x-httpd-php and is refused. An extension Unit does not know, such as .phtml or .inc, has an empty type, and the allow-list refuses that too. A refused request takes the share’s fallback when there is one, and gets a 403 response when there is not. Do not write the list as a refuse-list such as [“!application/x-httpd-php”]: a negated pattern does not exclude an empty type. See MIME filtering for the pattern syntax and the MIME type table for the limits of types, including the index file case.
The list above is a starting point. Add the types your site serves -- text/html, application/json, text/plain, the XML types, application/pdf, video/* -- or those files are not served.
{ "listeners": { "*:80": { "pass": "routes" } }, "routes": [ { "match": { "uri": [ "!/tests/qunit/*", "/cache/*", "/includes/*", "/languages/*", "/maintenance/*", "/tests/*", "/vendor/*" ] }, "action": { "return": 404 } }, { "match": { "uri": [ "/api.php", "/api.php/*", "/img_auth.php", "/img_auth.php/*", "/index.php", "/index.php/*", "/load.php", "/load.php/*", "/mw-config/*.php", "/opensearch_desc.php", "/opensearch_desc.php/*", "/rest.php", "/rest.php/*", "/tests/qunit/*.php", "/thumb.php", "/thumb.php/*", "/thumb_handler.php", "/thumb_handler.php/*" ] }, "action": { "pass": "applications/mw/direct" } }, { "match": { "uri": [ "!*.php", "!*.json", "!*.htaccess", "/extensions/*", "/images/*", "/resources/assets/*", "/resources/lib/*", "/resources/src/*", "/skins/*" ] }, "action": { "share": "/path/to/app$uri" } }, { "action": { "pass": "applications/mw/index" } } ], "applications": { "mw": { "type": "php", "targets": { "direct": { "root": "/path/to/app/" }, "index": { "root": "/path/to/app/", "script": "index.php" } } } } }
Note
The difference between the pass targets is their usage of the script setting:
- The direct target runs the .php script from the URI or defaults to index.php if the URI omits it.
- The index target specifies the script that Unit runs for any URIs the target receives.
Upload the updated configuration. Assuming the JSON above was added to
config.json. Run the following command as root:# curl -X PUT --data-binary @config.json --unix-socket \ /path/to/control.unit.sock http://localhost/config/
Note
The control socket path may vary; run unitd -h or see Startup and Shutdown for details.
Browse to http://localhost/mw-config/index.php and set MediaWiki up using the settings noted earlier:
Download the newly generated LocalSettings.php file and place it appropriately:
$ chmod 600 LocalSettings.php
Run the following commands (as root) to set the correct ownership:
# chown unit:unit LocalSettings.php
# mv LocalSettings.php /path/to/app/
After installation, add a match condition to the first step to disable access to the mw-config/ directory. Run the following command (as root):
# curl -X POST -d '"/mw-config/*"' \ --unix-socket /path/to/control.unit.sock \ http://localhost/config/routes/mediawiki/0/match/uri/ { "success": "Reconfiguration done." }
After a successful update, MediaWiki should be available on the listener’s IP address and port: