server { listen 8082; server_name _; # 安全 Header add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; add_header X-Frame-Options SAMEORIGIN; add_header X-Content-Type-Options nosniff; add_header X-XSS-Protection "1; mode=block"; add_header Content-Security-Policy "default-src 'self' data: blob: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:;" always; root /opt/course; try_files $uri $uri/ /index.html; #------------------------------------------------- # 前端应用 #------------------------------------------------- location = / { rewrite ^/ /course break; } location / { index index.html; try_files $uri $uri/ /index.html; expires 7d; add_header Cache-Control "public, max-age=604800, immutable"; } #------------------------------------------------- # OSS 静态目录(带目录索引) #------------------------------------------------- location ^~ /oss/ { alias /opt/course/oss/; index _; # 去掉默认的界面 autoindex on; # 开启目录索引 autoindex_exact_size off; # 文件大小人性化显示 autoindex_localtime on; # 显示本地时间 charset utf-8; expires 30d; add_header Cache-Control "public, max-age=2592000, immutable"; # 如果不做这个配置,点击目录下的txt文件,大部分浏览器默认是直接浏览的。这里通过添加响应头来控制。 if ($request_filename ~* ^.*?\.(html|txt|doc|pdf|rar|gz|zip|docx|exe|xlsx|ppt|pptx|conf)$){ add_header Content-Disposition 'attachment;'; } } #------------------------------------------------- # lua后端接口 #------------------------------------------------- # lua 文件上传接口 location = /api/upload { content_by_lua_file /opt/course/lua/course_upload.lua; } # lua 读取json文件 location ^~ /api/json/ { content_by_lua_file /opt/course/lua/course_query.lua; } location = /api/device/status { # 允许所有域名跨域 add_header 'Access-Control-Allow-Origin' '*'; add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS'; add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range'; add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range'; default_type application/json; content_by_lua_file /opt/course/lua/course_device_status.lua; } #------------------------------------------------- # 后端接口代理 #------------------------------------------------- location ^~ /api/ { default_type application/json; add_header 'Access-Control-Allow-Origin' '*' always; add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE' always; add_header 'Access-Control-Allow-Headers' 'Content-Type, Authorization, X-Requested-With' always; add_header 'Access-Control-Allow-Credentials' 'true' always; # 移除 rewrite,改用 proxy_pass 直接处理 proxy_pass http://124.222.28.5:7213/; proxy_set_header Host m1.apifoxmock.com; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # 处理代理失败的情况(如404) proxy_intercept_errors on; error_page 404 = @course_api_fallback; } location @course_api_fallback { default_type application/json; content_by_lua_file /opt/course/lua/course_query.lua; } }