43d86b4b6f
- /admin User account rows gain BLOCK/UNBLOCK, REMOVE/RESTORE and DELETE. Blocked = cannot sign in (sessions swept), removed = hidden from the strip and cannot sign in, both reversible; DELETE drops the account with its photos and recipes and unlinks the files. An allowlisted account is never a target, so an admin cannot moderate or delete itself. - Photo uploads move from a 3MB API cap / 4m nginx cap to 12MB / 16m, and the browser shrinks an oversized still before sending it (2048px JPEG, avatars 512px) so the declared type still matches the sniffed bytes. - The studio SAVE leaves the top bar and sits under the CREATE RECIPES tab, labelled SAVE RECIPES.
51 lines
1.9 KiB
Nginx Configuration File
51 lines
1.9 KiB
Nginx Configuration File
# Static SPA + API proxy. TLS/domain are terminated outside (Nginx Proxy
|
|
# Manager), so this container only ever speaks plain HTTP on port 80.
|
|
server {
|
|
listen 80;
|
|
server_name _;
|
|
root /usr/share/nginx/html;
|
|
index index.html;
|
|
|
|
# Static only, plus the API proxy below; a stricter CSP needs a per-app tune
|
|
# (canvas wasm, the QR image host) and belongs here once it is done.
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
add_header X-Frame-Options "DENY" always;
|
|
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
|
|
|
gzip on;
|
|
gzip_comp_level 5;
|
|
gzip_min_length 1024;
|
|
gzip_types text/css application/javascript application/json application/wasm image/svg+xml;
|
|
|
|
# canvas.wasm is ~8MB: immutable, hashed or not, it never changes under a
|
|
# given build. Fonts and the wall-frame artwork are likewise static.
|
|
location ~* ^/(wasm|assets)/ {
|
|
expires 30d;
|
|
add_header Cache-Control "public, immutable";
|
|
try_files $uri =404;
|
|
}
|
|
|
|
location /api/ {
|
|
# Resolved per request through Docker's embedded DNS, so the frontend can
|
|
# start before the API container without nginx refusing to boot.
|
|
resolver 127.0.0.11 valid=10s ipv6=off;
|
|
set $api_upstream http://api:3000;
|
|
proxy_pass $api_upstream$request_uri;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
# Hand the API the scheme the visitor actually used (TLS is terminated by
|
|
# Nginx Proxy Manager in front of this container) so it can mark the session
|
|
# cookie Secure. Falls back to nothing when that header is absent.
|
|
proxy_set_header X-Forwarded-Proto $http_x_forwarded_proto;
|
|
# Room for a full-size upload (the API caps photo bodies at 12m itself).
|
|
client_max_body_size 16m;
|
|
}
|
|
|
|
# SPA fallback: /app, /login and /signup are all index.html.
|
|
location / {
|
|
try_files $uri $uri/ /index.html;
|
|
}
|
|
}
|