64 lines
2.5 KiB
Text
64 lines
2.5 KiB
Text
server {
|
|
server_name visual.loki-code.dev;
|
|
root /var/www/visual.loki-code.dev/html;
|
|
index index.html;
|
|
|
|
# Forgejo's API sends no CORS headers, so the download page reads the
|
|
# release list through this cached proxy (5 min) instead of from the browser.
|
|
location = /api/releases {
|
|
proxy_pass https://git.wihuk.pro/api/v1/repos/boba/LoVisual/releases?limit=10;
|
|
proxy_ssl_server_name on;
|
|
proxy_set_header Host git.wihuk.pro;
|
|
proxy_set_header Authorization "";
|
|
proxy_set_header Cookie "";
|
|
proxy_hide_header Set-Cookie;
|
|
proxy_cache lv_releases;
|
|
proxy_cache_valid 200 5m;
|
|
proxy_cache_use_stale error timeout updating http_500 http_502 http_503;
|
|
add_header Cache-Control "public, max-age=60" always;
|
|
}
|
|
|
|
# The mod jar is served by nginx itself (not through the gateway) so the
|
|
# speed can be capped: ~6 Mbit/s per connection and at most 2 connections
|
|
# per client IP keep a flood of downloads from saturating the link.
|
|
location = /api/downloads/lovisual.jar {
|
|
alias /opt/lovisual/backend/downloads/lovisual.jar;
|
|
default_type application/java-archive;
|
|
add_header Content-Disposition 'attachment; filename="lovisual.jar"' always;
|
|
limit_rate 750k;
|
|
limit_conn lv_downloads 2;
|
|
limit_conn_status 429;
|
|
}
|
|
|
|
location = /api/downloads/lovisual.jar.sha256 {
|
|
alias /opt/lovisual/backend/downloads/lovisual.jar.sha256;
|
|
default_type text/plain;
|
|
}
|
|
|
|
location /api/ {
|
|
proxy_pass http://127.0.0.1:8080/;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header X-Forwarded-Proto $scheme;
|
|
# The backend scopes the refresh cookie to Path=/auth, but the frontend calls it
|
|
# under /api/auth/* through this proxy — without this rewrite the browser never
|
|
# sends the cookie back on /api/auth/refresh and the session is lost on reload.
|
|
proxy_cookie_path /auth /api/auth;
|
|
}
|
|
|
|
# Fingerprinted build output (assets/<name>-<hash>.js/.css/...) -- the filename changes
|
|
# whenever the content does, so it's safe to cache "forever"; a stale copy is never served
|
|
# under the old URL after a deploy.
|
|
location /assets/ {
|
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
|
try_files $uri =404;
|
|
}
|
|
|
|
location / {
|
|
try_files $uri /index.html;
|
|
}
|
|
|
|
listen 80;
|
|
}
|