feat(cinny): nginx for Element Call on call.chat.lotusguild.org (cinny #43)
Lint / Shell (shellcheck) (push) Successful in 21s
Lint / JS (eslint) (push) Successful in 14s
Lint / No secrets in webhook configs (push) Successful in 6s
Lint / Landing page is rendered (matrix (push) Successful in 6s
Lint / Python (ruff) (push) Successful in 7s
Lint / Python deps (pip-audit) (push) Successful in 52s
Lint / Secret scan (gitleaks) (push) Successful in 8s
Lint / Shell (shellcheck) (pull_request) Successful in 17s
Lint / JS (eslint) (pull_request) Successful in 13s
Lint / No secrets in webhook configs (pull_request) Successful in 6s
Lint / Landing page is rendered (matrix (pull_request) Successful in 6s
Lint / Python (ruff) (pull_request) Successful in 8s
Lint / Python deps (pip-audit) (pull_request) Successful in 53s
Lint / Secret scan (gitleaks) (pull_request) Successful in 8s
Lint / Shell (shellcheck) (push) Successful in 21s
Lint / JS (eslint) (push) Successful in 14s
Lint / No secrets in webhook configs (push) Successful in 6s
Lint / Landing page is rendered (matrix (push) Successful in 6s
Lint / Python (ruff) (push) Successful in 7s
Lint / Python deps (pip-audit) (push) Successful in 52s
Lint / Secret scan (gitleaks) (push) Successful in 8s
Lint / Shell (shellcheck) (pull_request) Successful in 17s
Lint / JS (eslint) (pull_request) Successful in 13s
Lint / No secrets in webhook configs (pull_request) Successful in 6s
Lint / Landing page is rendered (matrix (pull_request) Successful in 6s
Lint / Python (ruff) (pull_request) Successful in 8s
Lint / Python deps (pip-audit) (pull_request) Successful in 53s
Lint / Secret scan (gitleaks) (pull_request) Successful in 8s
- cinny/nginx.conf: a call.chat.lotusguild.org server block that serves ONLY /public/element-call/ (the same files chat.lotusguild.org already serves there) and 404s everything else, including source maps and dotfiles. - cinny/nginx-security-headers-call.conf (new snippet): frame-ancestors https://chat.lotusguild.org instead of X-Frame-Options SAMEORIGIN, which would block the now cross-origin parent. - cinny/nginx-security-headers.conf: the app's Permissions-Policy delegates autoplay/camera/display-capture/microphone to the call origin (without it the cross-origin frame's getUserMedia is refused). Outer quotes switched to single: the inner "origin" quotes broke nginx parsing. Nothing changes for users until config.json sets elementCallUrl (separate step). Snippets are installed by hand on LXC 106; nginx.conf deploys on merge. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
1dccca914c
commit
9c5a183025
@@ -108,3 +108,53 @@ server {
|
||||
rewrite ^(.+)$ /index.html break;
|
||||
}
|
||||
}
|
||||
|
||||
# [cinny #43] Element Call on its own origin. The web app frames
|
||||
# https://call.chat.lotusguild.org/public/element-call/index.html (config.json
|
||||
# `elementCallUrl`), so the call page can no longer read the app's storage
|
||||
# (login token, crypto store) or use its service worker. Serves ONLY the call
|
||||
# page — the same files as chat.lotusguild.org/public/element-call/ — and 404s
|
||||
# everything else, so this hostname exposes nothing new.
|
||||
server {
|
||||
listen 80;
|
||||
listen [::]:80;
|
||||
server_name call.chat.lotusguild.org;
|
||||
|
||||
brotli on;
|
||||
brotli_static on;
|
||||
brotli_comp_level 6;
|
||||
brotli_types text/plain text/css application/javascript application/json
|
||||
image/svg+xml application/wasm font/woff2;
|
||||
|
||||
root /var/www/html;
|
||||
server_tokens off;
|
||||
limit_req zone=chat_limit burst=60 nodelay;
|
||||
limit_conn chat_conn 25;
|
||||
|
||||
include snippets/cinny-security-headers-call.conf;
|
||||
|
||||
location ^~ /public/element-call/ {
|
||||
include snippets/cinny-security-headers-call.conf;
|
||||
location ~* \.map$ {
|
||||
return 404;
|
||||
}
|
||||
location ~ /\. {
|
||||
return 404;
|
||||
}
|
||||
location ~* \.html$ {
|
||||
include snippets/cinny-security-headers-call.conf;
|
||||
expires -1;
|
||||
add_header Cache-Control "no-cache, no-store, must-revalidate" always;
|
||||
}
|
||||
location ~* \.(?:js|css|woff2?|png|svg|ico|webp|wasm)$ {
|
||||
include snippets/cinny-security-headers-call.conf;
|
||||
expires 1y;
|
||||
add_header Cache-Control "public, immutable" always;
|
||||
}
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
location / {
|
||||
return 404;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user