LoVisual/backend/deploy/nginx-visual.loki-code.dev.conf
loki5512344 9744dc7f24
fix(frontend): add a real robots.txt, cache hashed assets forever
Lighthouse audit findings:
- No robots.txt existed, so nginx's SPA fallback (try_files -> index.html)
  served the React app's HTML at /robots.txt -- crawlers got 44 "syntax
  not understood" lines instead of directives.
- No Cache-Control on /assets/*, so every visit re-fetched a hashed,
  content-addressed bundle that can never actually change under that
  URL. Lighthouse estimated 936 KiB/visit wasted on this alone.

Claude-Session: https://claude.ai/code/session_01F1M1Jic1wTSn4igUENynmZ
2026-09-30 15:40:04 +02:00

32 lines
1.2 KiB
Text

server {
server_name visual.loki-code.dev;
root /var/www/visual.loki-code.dev/html;
index index.html;
location /api/ {
proxy_pass http://127.0.0.1:8080/;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
# The backend scopes the refresh cookie to Path=/auth, but the frontend calls it
# under /api/auth/* through this proxy — without this rewrite the browser never
# sends the cookie back on /api/auth/refresh and the session is lost on reload.
proxy_cookie_path /auth /api/auth;
}
# Fingerprinted build output (assets/<name>-<hash>.js/.css/...) -- the filename changes
# whenever the content does, so it's safe to cache "forever"; a stale copy is never served
# under the old URL after a deploy.
location /assets/ {
add_header Cache-Control "public, max-age=31536000, immutable" always;
try_files $uri =404;
}
location / {
try_files $uri /index.html;
}
listen 80;
}