server { server_name visual.loki-code.dev; root /var/www/visual.loki-code.dev/html; index index.html; # Forgejo's API sends no CORS headers, so the download page reads the # release list through this cached proxy (5 min) instead of from the browser. location = /api/releases { proxy_pass https://git.wihuk.pro/api/v1/repos/boba/LoVisual/releases?limit=10; proxy_ssl_server_name on; proxy_set_header Host git.wihuk.pro; proxy_set_header Authorization ""; proxy_set_header Cookie ""; proxy_hide_header Set-Cookie; proxy_cache lv_releases; proxy_cache_valid 200 5m; proxy_cache_use_stale error timeout updating http_500 http_502 http_503; add_header Cache-Control "public, max-age=60" always; } location /api/ { proxy_pass http://127.0.0.1:8080/; proxy_http_version 1.1; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # The backend scopes the refresh cookie to Path=/auth, but the frontend calls it # under /api/auth/* through this proxy — without this rewrite the browser never # sends the cookie back on /api/auth/refresh and the session is lost on reload. proxy_cookie_path /auth /api/auth; } # Fingerprinted build output (assets/-.js/.css/...) -- the filename changes # whenever the content does, so it's safe to cache "forever"; a stale copy is never served # under the old URL after a deploy. location /assets/ { add_header Cache-Control "public, max-age=31536000, immutable" always; try_files $uri =404; } location / { try_files $uri /index.html; } listen 80; }