I'm struggling on setting up restrictions by request method in the nginx location block. I want to allow GET for everyone, however I want to allow DELETE as well but for certain IP addresses / CIDR only. How can I achieve this?
I tried with this, but that seems do not work as expected:
location /data {
if ($request_method !~ ^(DELETE|GET) {
return 405;
}
limit_except GET {
allow all;
}
allow 10.10.10.0/24;
allow 127.0.0.1;
deny all;
}