Files
RecipesCam/docker/frontend/nginx.conf
T
3dtours 2ced93a425 A fixed mask EXPOSURE that never arrives: the shell stops being cacheable by guesswork
The request was a mask's EXPOSURE losing hue, and the mask pass has not done that
since 6d60d45: measured today through a page the service worker controls, with an
ellipse over the whole frame and +1 EV, the pixels inside move exactly as the
frame's own knob moves them — identical to the byte (mask+1 vs frame+1 over four
codes: 619 pixels of 1,709,450, all of them on the rim), and the hue each one
leaves behind is the same distribution to a hundredth of a degree over the
370,606 pixels that carry a hue in both reads (mean 2.07°, p99 15.31° for the mask
against 15.32° for the frame; on the vivid pixels, mean 0.83° at +1 EV). The one
place that still says otherwise is a doc on the Android branch, whose §3.2 quotes
the old line.

But the symptom is real, and the build that produces it is the one from before
that commit, where maskAdjust multiplied the three channels by the stop:

    c = c * half(pow(2.0, a.x));

Three channels clip by three different amounts, so the differences between them
stop being scaled together and the hue goes with them. That bundle could still be
what a visitor runs, because of two files the deploy never took away:

- index.html was the only document the server handed over with no Cache-Control
  at all (the .mjs, /assets, /wasm and /models locations all name their policy,
  sw.js and the manifest both opted out). With no header the browser is free to
  guess a freshness window out of Last-Modified — a tenth of the file's age — and
  answer a navigation from its own cache for hours after a deploy. The page it
  answers with names the previous build's hashed bundle, so the previous shader
  is what runs, and a hard reload is the only way out. The SPA fallback lands on
  the same file (an internal redirect re-matches locations), so /app and /library
  were covered by the same guess.

- sw.js is the second place the pin lived. Its navigations are network-first, but
  a plain fetch is not the network: it can be answered by the browser's cache, so
  the network never came first — and the old shell's hashed bundle, once fetched,
  is a STATIC path that the cache-first rule serves forever.

So: nginx names the policy for the shell, with the isolation pair restated
because an add_header in a location drops every inherited one and index.html is
the document that needs them — the wasm renderer's SharedArrayBuffer is behind
that pair. The worker reads its navigations past the browser's cache, precaches
the shell the same way (a cache.add of '/' consults that cache like any other
fetch, so a shell read inside a stale window would be stored as the offline shell
of the build that replaced it), and VERSION goes to v2, whose activate drops the
cache the old worker pinned — the old shell and the old bundle with it.

The root fix is still 6d60d45: this commit is what lets it reach the browser.

Verified: nginx -t on the shipped config, and a container of this config against
a copy of index.html hands / and /app `Cache-Control: no-cache` with all five
original headers intact, while /assets/index-abc.js keeps `public, immutable`
(30 days) — the exact location does not shadow the hashed bundle. node --check on
sw.js. The measurements above come from the live 8090 build inside a persistent
profile whose page is controlled by the worker (controlled true,
crossOriginIsolated true, bundle index-CKOd57MG.js), the same session that pinned
the build the fix is about.

Co-authored-by: PenguinHarness <noreply@penguin.local>
2026-09-29 18:33:10 +07:00

138 lines
6.4 KiB
Nginx Configuration File

# Static SPA + API proxy. TLS/domain are terminated outside (Nginx Proxy
# Manager), so this container only ever speaks plain HTTP on port 80.
server {
listen 80;
server_name _;
root /usr/share/nginx/html;
index index.html;
# Static only, plus the API proxy below; a stricter CSP needs a per-app tune
# (canvas wasm, the QR image host) and belongs here once it is done.
# Cross-origin isolation: super-resolution runs onnxruntime's threaded wasm,
# which needs a SharedArrayBuffer, which the browser only hands over when the
# page is isolated. Both headers are required, and both must also sit on the
# script responses a nested worker fetches — see the two locations below.
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
gzip on;
gzip_comp_level 5;
gzip_min_length 1024;
gzip_types text/css application/javascript application/json application/wasm image/svg+xml;
# nginx's stock mime.types has no .mjs, and the browser refuses to run a module
# the server hands over as octet-stream: onnxruntime's glue is one of those.
# First match wins among regex locations, so this one stands before the
# /wasm/ block that would otherwise swallow the file.
# (Both locations below restate the isolation headers from above: an add_header
# in a location drops every add_header inherited, and a worker script is fetched
# under the embedder's COEP — Chromium blocks it as
# `coep-frame-resource-needs-coep-header` without them.)
location ~* \.mjs$ {
types { application/javascript mjs; }
expires 30d;
add_header Cache-Control "public, immutable";
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
try_files $uri =404;
}
# canvas.wasm is ~8MB and the super-resolution model is ~5MB: immutable, hashed
# or not, they never change under a given build. Fonts and the wall-frame
# artwork are likewise static.
location ~* ^/(wasm|models|assets)/ {
expires 30d;
add_header Cache-Control "public, immutable";
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
try_files $uri =404;
}
# The two files whose names never change but whose contents must: a cached worker
# keeps answering with the previous build's shell long after the deploy that
# replaced it, and a cached manifest keeps pointing at the icon set it shipped with.
# Nothing else would ever flush them, which is exactly why they opt out of the
# long-lived caching above. The worker is a script under the embedder's COEP like
# the .mjs files, so it restates the two isolation headers for the same reason.
location = /sw.js {
add_header Cache-Control "no-cache";
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
try_files $uri =404;
}
location = /manifest.json {
add_header Cache-Control "no-cache";
try_files $uri =404;
}
# The shell is the third name that never changes and whose contents do: with no
# header of its own a browser is free to guess a freshness window out of
# Last-Modified — a tenth of the file's age — and hand a visitor the PREVIOUS
# build's index.html for hours after a deploy. That page names that build's
# hashed bundle, so a fixed shader keeps running as the broken one and a hard
# reload is the only way out. The SPA fallback below lands here too (the
# internal redirect re-matches locations), so /app and /library are covered by
# the same line.
# (Restated: an add_header in a location drops every add_header inherited, and
# this document needs the isolation pair for the wasm renderer.)
location = /index.html {
add_header Cache-Control "no-cache";
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "DENY" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
try_files $uri =404;
}
# The one route that carries a whole data dir back in (see /api/admin/restore
# — who may call it is the API's own admin check, done before it reads a byte).
# The upload cap that holds everywhere else would reject it, and unpacking the
# archive plus the restart takes longer than the stock read timeout. nginx
# takes the longest matching prefix, so this one holds for that route while
# /api/ below keeps the rest.
location /api/admin/restore {
resolver 127.0.0.11 valid=10s ipv6=off;
set $api_upstream http://api:3000;
proxy_pass $api_upstream$request_uri;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
client_max_body_size 0;
proxy_read_timeout 600s;
proxy_send_timeout 600s;
}
location /api/ {
# Resolved per request through Docker's embedded DNS, so the frontend can
# start before the API container without nginx refusing to boot.
resolver 127.0.0.11 valid=10s ipv6=off;
set $api_upstream http://api:3000;
proxy_pass $api_upstream$request_uri;
proxy_http_version 1.1;
# $http_host, not $host: keep the port when the visitor hits this container
# directly (localhost:8090), since the API builds the verification link from
# the forwarded host.
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# Hand the API the scheme the visitor actually used (TLS is terminated by
# Nginx Proxy Manager in front of this container) so it can mark the session
# cookie Secure. Falls back to nothing when that header is absent.
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
# Room for a full-size upload (the API caps photo bodies at 12m itself).
client_max_body_size 16m;
}
# SPA fallback: /app, /login and /signup are all index.html.
location / {
try_files $uri $uri/ /index.html;
}
}