server { listen 443 ssl; http2 on; server_name _; # SSL证书路径 ssl_certificate /usr/local/openresty/nginx/ssl/ali.haijunit.icu.pem; ssl_certificate_key /usr/local/openresty/nginx/ssl/ali.haijunit.icu.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers 'EECDH+AESGCM:EECDH+CHACHA20:EECDH+AES256:!aNULL:!MD5:!RC4'; ssl_prefer_server_ciphers on; ssl_session_cache shared:SSL:50m; ssl_session_timeout 10m; ssl_stapling on; ssl_stapling_verify on; # 可选:显式指定 TLSv1.3 cipher(仅 OpenSSL 1.1.1+ 支持) ssl_conf_command Ciphersuites TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256; # 安全 Header add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; add_header X-Frame-Options SAMEORIGIN; add_header X-Content-Type-Options nosniff; add_header X-XSS-Protection "1; mode=block"; add_header Content-Security-Policy "default-src 'self' data: blob: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:;" always; root html; try_files $uri $uri/ /index.html; #------------------------------------------------- # 通用业务 #------------------------------------------------- location = / { rewrite ^/ /course break; } #------------------------------------------------- # 前端应用 #------------------------------------------------- location / { index index.html; try_files $uri $uri/ /index.html; expires 7d; add_header Cache-Control "public, max-age=604800, immutable"; } #------------------------------------------------- # 静态资源缓存 + 防盗链 #------------------------------------------------- location ~* \.(js|css|png|jpg|jpeg|gif|svg|woff2?|ttf|ico)$ { expires 30d; access_log off; add_header Cache-Control "public, max-age=2592000, immutable"; } #------------------------------------------------- # 课程管理 #------------------------------------------------- location ^~ /course/ { default_type application/json; add_header 'Access-Control-Allow-Origin' '*'; add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range'; # 移除 rewrite,改用 proxy_pass 直接处理 proxy_pass http://127.0.0.1:8082/; } #------------------------------------------------- # 健康检查 #------------------------------------------------- location /health { access_log off; return 200 'healthy'; add_header Content-Type text/plain; } #------------------------------------------------- # 错误页 #------------------------------------------------- error_page 403 /403.html; error_page 404 /404.html; error_page 500 502 503 504 /50x.html; location = /403.html { } location = /404.html { } location = /50x.html { } #------------------------------------------------- # 安全配置 #------------------------------------------------- # 安全配置:禁止访问隐藏文件 location ~ /\. { deny all; access_log off; log_not_found off; } # 安全配置:禁止访问常见敏感文件 location ~* (\.log|\.sql|\.env|\.git) { deny all; access_log off; log_not_found off; } } #===================================================== # HTTP -> HTTPS 自动跳转 #===================================================== server { listen 80; server_name _; return 301 https://$host$request_uri; }