server { server_name visual.loki-code.dev; root /var/www/visual.loki-code.dev/html; index index.html; location /api/ { proxy_pass http://127.0.0.1:8080/; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # The backend scopes the refresh cookie to Path=/auth, but the frontend calls it # under /api/auth/* through this proxy — without this rewrite the browser never # sends the cookie back on /api/auth/refresh and the session is lost on reload. proxy_cookie_path /auth /api/auth; } # Fingerprinted build output (assets/-.js/.css/...) -- the filename changes # whenever the content does, so it's safe to cache "forever"; a stale copy is never served # under the old URL after a deploy. location /assets/ { add_header Cache-Control "public, max-age=31536000, immutable" always; try_files $uri =404; } location / { try_files $uri /index.html; } listen 80; }