server { server_name visual.loki-code.dev; root /var/www/visual.loki-code.dev/html; index index.html; # Forgejo's API sends no CORS headers, so the download page reads the # release list through this cached proxy (5 min) instead of from the browser. location = /api/releases { proxy_pass https://git.wihuk.pro/api/v1/repos/boba/LoVisual/releases?limit=10; proxy_ssl_server_name on; proxy_set_header Host git.wihuk.pro; proxy_set_header Authorization ""; proxy_set_header Cookie ""; proxy_hide_header Set-Cookie; proxy_cache lv_releases; proxy_cache_valid 200 5m; proxy_cache_use_stale error timeout updating http_500 http_502 http_503; add_header Cache-Control "public, max-age=60" always; } # The mod jar is served by nginx itself (not through the gateway) so the # speed can be capped: ~6 Mbit/s per connection and at most 2 connections # per client IP keep a flood of downloads from saturating the link. location = /api/downloads/lovisual.jar { alias /opt/lovisual/backend/downloads/lovisual.jar; default_type application/java-archive; add_header Content-Disposition 'attachment; filename="lovisual.jar"' always; limit_rate 750k; limit_conn lv_downloads 2; limit_conn_status 429; } location = /api/downloads/lovisual.jar.sha256 { alias /opt/lovisual/backend/downloads/lovisual.jar.sha256; default_type text/plain; } location /api/ { proxy_pass http://127.0.0.1:8080/; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # The backend scopes the refresh cookie to Path=/auth, but the frontend calls it # under /api/auth/* through this proxy — without this rewrite the browser never # sends the cookie back on /api/auth/refresh and the session is lost on reload. proxy_cookie_path /auth /api/auth; } # Fingerprinted build output (assets/-.js/.css/...) -- the filename changes # whenever the content does, so it's safe to cache "forever"; a stale copy is never served # under the old URL after a deploy. location /assets/ { add_header Cache-Control "public, max-age=31536000, immutable" always; try_files $uri =404; } location / { try_files $uri /index.html; } listen 80; }