location /public { root /data; } # WebSocket 支持 location /ws/ { proxy_pass http://backend; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $http_host; proxy_set_header X-Real-IP __IP_HEADER__; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # WebSocket 超时设置 proxy_connect_timeout 7d; proxy_send_timeout 7d; proxy_read_timeout 7d; } location /api { include api_proxy.conf; } # location /admin { # root /app/dist/admin; # try_files $uri $uri/ /index.html =404; # } location /.well-known { alias /data/ssl/.well-known; } # 注意:location 里一旦出现 add_header,http 级的 add_header 就不再继承, # 所以下面两个 block 都要把 nginx.conf 里的安全头重新写一遍。 # 构建产物文件名带内容 hash,内容一变文件名就变,可以永久缓存。 # 命中后浏览器直接读磁盘,不再发条件请求。 location /assets/ { root /app/dist; expires 1y; add_header Cache-Control "public, immutable"; add_header X-XSS-Protection "1; mode=block" always; add_header X-Frame-Options SAMEORIGIN always; add_header X-Content-Type-Options nosniff always; access_log off; } location / { root /app/dist; try_files $uri $uri/ /index.html =404; # index.html 引用着带 hash 的文件名,必须每次回源校验, # 否则发新版后学生刷不到。no-cache 是"缓存但每次校验",命中走 304。 add_header Cache-Control "no-cache"; add_header X-XSS-Protection "1; mode=block" always; add_header X-Frame-Options SAMEORIGIN always; add_header X-Content-Type-Options nosniff always; }