diff --git a/nginx.conf b/nginx.conf index d6bbd54..edad655 100644 --- a/nginx.conf +++ b/nginx.conf @@ -1,47 +1,27 @@ server { listen 80; - server_name localhost; + server_name _; + root /usr/share/nginx/html; index index.html; - add_header X-Frame-Options "DENY" always; - add_header X-Content-Type-Options "nosniff" always; - add_header X-XSS-Protection "1; mode=block" always; - add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; preload" always; - # add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; style-src 'self' 'unsafe-inline';" always; - add_header Referrer-Policy "strict-origin-when-cross-origin" always; - - location /static/ { - expires 1y; - add_header Cache-Control "public, no-transform"; - } - + # SPA fallback location / { try_files $uri $uri/ /index.html; - expires -1; add_header Cache-Control "no-store, no-cache, must-revalidate"; } - # location /health { - # access_log off; - # return 200; - # } - - location ~ /\. { - deny all; - return 403; + # Vite build outputs to /assets by default + location /assets/ { + expires 1y; + add_header Cache-Control "public, immutable"; + try_files $uri =404; } - error_page 500 502 503 504 /50x.html; - location = /50x.html { - root /usr/share/nginx/html; - internal; + # optional: favicon (avoid noisy logs if missing) + location = /favicon.ico { + try_files $uri =204; + access_log off; + log_not_found off; } - - gzip on; - gzip_vary on; - gzip_min_length 10240; - gzip_proxied expired no-cache no-store private auth; - gzip_types text/plain text/css text/xml text/javascript application/x-javascript application/xml application/javascript; - gzip_disable "MSIE [1-6]\."; -} \ No newline at end of file +}