handoff pass: vendored sveltia bundle, astro pinned ^7.2.10, root README + refreshed deploy runbook, review fixes (coverless card grid, shared NewsCard/lib, real site origin, nginx security headers, linger step, dead config removed, preview.css sync, tsconfig)

This commit is contained in:
2026-09-03 14:56:53 +02:00
parent c64528a1d3
commit cec8018c18
35 changed files with 4095 additions and 2111 deletions
+19 -4
View File
@@ -7,28 +7,43 @@ server {
server_name _;
root /srv/releases/current;
charset utf-8;
server_tokens off;
error_page 404 /404.html; # Astro emits 404.html at the site root
# Directory redirects (/admin -> /admin/) must stay relative: an absolute
# redirect is built from listen port 80 and loses the real port whenever the
# site is reached through a tunnel or a proxy on a non-default port.
absolute_redirect off;
# Security headers are REPEATED in every location on purpose: nginx
# `add_header` inheritance is all-or-nothing — any add_header in a location
# discards ALL server-level ones, so server-level headers would silently
# vanish. `always` keeps them on error responses (404) too.
# Fingerprinted build assets (/_astro/<name>.<hash>.*) — immutable
location /_astro/ {
add_header Cache-Control "public, max-age=31536000, immutable";
add_header Cache-Control "public, max-age=31536000, immutable" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
# Editor-uploaded media (stable paths, may be re-uploaded) — short cache
location /uploads/ {
add_header Cache-Control "public, max-age=3600";
add_header Cache-Control "public, max-age=3600" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
# Everything else: HTML pages, feeds, /admin (Sveltia is static files too)
location / {
try_files $uri $uri/ =404;
add_header Cache-Control "no-cache";
add_header Cache-Control "no-cache" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header X-Frame-Options "SAMEORIGIN" always;
}
gzip on;
gzip_types text/css application/javascript application/json image/svg+xml application/rss+xml text/xml;
gzip_types text/css application/javascript application/json image/svg+xml application/rss+xml text/xml application/xml;
}