Files
matrix/cinny/nginx.conf
T
Lotus CIandClaude Opus 5.5 9c5a183025
Lint / Shell (shellcheck) (push) Successful in 21s
Lint / JS (eslint) (push) Successful in 14s
Lint / No secrets in webhook configs (push) Successful in 6s
Lint / Landing page is rendered (matrix (push) Successful in 6s
Lint / Python (ruff) (push) Successful in 7s
Lint / Python deps (pip-audit) (push) Successful in 52s
Lint / Secret scan (gitleaks) (push) Successful in 8s
Lint / Shell (shellcheck) (pull_request) Successful in 17s
Lint / JS (eslint) (pull_request) Successful in 13s
Lint / No secrets in webhook configs (pull_request) Successful in 6s
Lint / Landing page is rendered (matrix (pull_request) Successful in 6s
Lint / Python (ruff) (pull_request) Successful in 8s
Lint / Python deps (pip-audit) (pull_request) Successful in 53s
Lint / Secret scan (gitleaks) (pull_request) Successful in 8s
feat(cinny): nginx for Element Call on call.chat.lotusguild.org (cinny #43)
- cinny/nginx.conf: a call.chat.lotusguild.org server block that serves ONLY
  /public/element-call/ (the same files chat.lotusguild.org already serves
  there) and 404s everything else, including source maps and dotfiles.
- cinny/nginx-security-headers-call.conf (new snippet): frame-ancestors
  https://chat.lotusguild.org instead of X-Frame-Options SAMEORIGIN, which
  would block the now cross-origin parent.
- cinny/nginx-security-headers.conf: the app's Permissions-Policy delegates
  autoplay/camera/display-capture/microphone to the call origin (without it
  the cross-origin frame's getUserMedia is refused). Outer quotes switched to
  single: the inner "origin" quotes broke nginx parsing.

Nothing changes for users until config.json sets elementCallUrl (separate
step). Snippets are installed by hand on LXC 106; nginx.conf deploys on merge.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PPmy3tPq869XDW4njjVaKA
2026-09-26 23:24:32 -04:00

161 lines
5.6 KiB
Nginx Configuration File

server {
listen 80;
listen [::]:80;
server_name chat.lotusguild.org;
# Brotli compression (better than gzip for modern browsers)
brotli on;
brotli_static on;
brotli_comp_level 6;
brotli_types text/plain text/css application/javascript application/json
image/svg+xml application/wasm font/woff2;
root /var/www/html;
server_tokens off;
client_max_body_size 50m;
limit_req zone=chat_limit burst=60 nodelay;
limit_conn chat_conn 25;
index index.html;
# Security headers (incl. CSP) — see the snippet
include snippets/cinny-security-headers.conf;
# HSTS: TLS terminates upstream (this server is listen 80), so this reaches
# the browser only if the front proxy passes upstream response headers
# through; otherwise set it at the TLS terminator. includeSubDomains covers
# all *.lotusguild.org (all HTTPS); `preload` is inert until submitted to
# hstspreload.org.
# Permissions-Policy: allow only what the app uses (self) — calls
# (camera/microphone/display-capture), location share (geolocation), sounds
# (autoplay), Element Call (fullscreen/encrypted-media) — and deny the rest.
# Block all source map files and dotfiles from public access
location ~* \.(js|css)\.map$ {
deny all;
return 404;
}
location ~ /\. {
deny all;
return 404;
}
location = /netlify.toml {
deny all;
return 404;
}
# Service worker must never be cached so updates are picked up immediately
location = /sw.js {
include snippets/cinny-security-headers.conf;
expires -1;
add_header Cache-Control "no-cache, no-store, must-revalidate" always;
}
# Bundled Element Call: framed by the app itself, so it must not carry the
# app CSP (frame-ancestors 'none' blocked every web call). Same caching as
# below: HTML never cached, hashed assets for a year.
location ^~ /public/element-call/ {
include snippets/cinny-security-headers-framed.conf;
location ~* \.html$ {
include snippets/cinny-security-headers-framed.conf;
expires -1;
add_header Cache-Control "no-cache, no-store, must-revalidate" always;
}
location ~* \.(?:js|css|woff2?|png|svg|ico|webp|wasm)$ {
include snippets/cinny-security-headers-framed.conf;
expires 1y;
add_header Cache-Control "public, immutable" always;
}
}
# Cache content-addressed static assets aggressively
location ~* \.(?:js|css|woff2?|png|svg|ico|webp)$ {
include snippets/cinny-security-headers.conf;
expires 1y;
add_header Cache-Control "public, immutable" always;
}
# Never cache HTML or JSON (index.html, config.json, manifest.json)
location ~* \.(json|html)$ {
include snippets/cinny-security-headers.conf;
expires -1;
add_header Cache-Control "no-cache, no-store, must-revalidate" always;
}
# [Gitea #155] PWA share target. The service worker normally answers this
# POST itself; if it isn't controlling the page yet, land on /share
# (the shared files are lost, but nothing 405s).
location = /share-target {
absolute_redirect off;
return 303 /share;
}
# Auto-deploy webhook — proxied to local webhook service
location = /hooks/lotus-deploy {
proxy_pass http://127.0.0.1:9001/hooks/lotus-deploy;
proxy_set_header Host $host;
proxy_read_timeout 300;
proxy_connect_timeout 5;
}
location / {
rewrite ^/config\.json$ /config.json break;
rewrite ^/manifest\.json$ /manifest.json break;
rewrite ^/sw\.js$ /sw.js break;
rewrite ^/pdf\.worker\.min\.js$ /pdf.worker.min.js break;
rewrite ^/public/(.*)$ /public/$1 break;
rewrite ^/assets/(.*)$ /assets/$1 break;
rewrite ^(.+)$ /index.html break;
}
}
# [cinny #43] Element Call on its own origin. The web app frames
# https://call.chat.lotusguild.org/public/element-call/index.html (config.json
# `elementCallUrl`), so the call page can no longer read the app's storage
# (login token, crypto store) or use its service worker. Serves ONLY the call
# page — the same files as chat.lotusguild.org/public/element-call/ — and 404s
# everything else, so this hostname exposes nothing new.
server {
listen 80;
listen [::]:80;
server_name call.chat.lotusguild.org;
brotli on;
brotli_static on;
brotli_comp_level 6;
brotli_types text/plain text/css application/javascript application/json
image/svg+xml application/wasm font/woff2;
root /var/www/html;
server_tokens off;
limit_req zone=chat_limit burst=60 nodelay;
limit_conn chat_conn 25;
include snippets/cinny-security-headers-call.conf;
location ^~ /public/element-call/ {
include snippets/cinny-security-headers-call.conf;
location ~* \.map$ {
return 404;
}
location ~ /\. {
return 404;
}
location ~* \.html$ {
include snippets/cinny-security-headers-call.conf;
expires -1;
add_header Cache-Control "no-cache, no-store, must-revalidate" always;
}
location ~* \.(?:js|css|woff2?|png|svg|ico|webp|wasm)$ {
include snippets/cinny-security-headers-call.conf;
expires 1y;
add_header Cache-Control "public, immutable" always;
}
try_files $uri =404;
}
location / {
return 404;
}
}