443.conf 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196
  1. server {
  2. listen 443 ssl;
  3. http2 on;
  4. server_name _;
  5. # SSL证书路径
  6. ssl_certificate /usr/local/openresty/nginx/ssl/ali.haijunit.icu.pem;
  7. ssl_certificate_key /usr/local/openresty/nginx/ssl/ali.haijunit.icu.key;
  8. ssl_protocols TLSv1.2 TLSv1.3;
  9. ssl_ciphers 'EECDH+AESGCM:EECDH+CHACHA20:EECDH+AES256:!aNULL:!MD5:!RC4';
  10. ssl_prefer_server_ciphers on;
  11. ssl_session_cache shared:SSL:50m;
  12. ssl_session_timeout 10m;
  13. ssl_stapling on;
  14. ssl_stapling_verify on;
  15. # 可选:显式指定 TLSv1.3 cipher(仅 OpenSSL 1.1.1+ 支持)
  16. ssl_conf_command Ciphersuites TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256;
  17. # 安全 Header
  18. add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
  19. add_header X-Frame-Options SAMEORIGIN;
  20. add_header X-Content-Type-Options nosniff;
  21. add_header X-XSS-Protection "1; mode=block";
  22. add_header Content-Security-Policy "default-src 'self' data: blob: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:;" always;
  23. root html;
  24. try_files $uri $uri/ /index.html;
  25. #-------------------------------------------------
  26. # 通用业务
  27. #-------------------------------------------------
  28. location = / {
  29. rewrite ^/ /course break;
  30. }
  31. # lua 文件上传接口
  32. location = /api/upload {
  33. content_by_lua_file /usr/local/openresty/lua/file_upload.lua;
  34. }
  35. # lua 读取json文件
  36. location /api/json/ {
  37. content_by_lua_file /usr/local/openresty/lua/query_json.lua;
  38. }
  39. #-------------------------------------------------
  40. # 前端应用
  41. #-------------------------------------------------
  42. location / {
  43. index index.html;
  44. try_files $uri $uri/ /index.html;
  45. expires 7d;
  46. add_header Cache-Control "public, max-age=604800, immutable";
  47. }
  48. #-------------------------------------------------
  49. # 静态资源缓存 + 防盗链
  50. #-------------------------------------------------
  51. location ~* \.(js|css|png|jpg|jpeg|gif|svg|woff2?|ttf|ico)$ {
  52. expires 30d;
  53. access_log off;
  54. add_header Cache-Control "public, max-age=2592000, immutable";
  55. }
  56. #-------------------------------------------------
  57. # OSS 静态目录(带目录索引)
  58. #-------------------------------------------------
  59. location ^~ /oss/ {
  60. alias /opt/oss/;
  61. index _; # 去掉默认的界面
  62. autoindex on; # 开启目录索引
  63. autoindex_exact_size off; # 文件大小人性化显示
  64. autoindex_localtime on; # 显示本地时间
  65. charset utf-8;
  66. expires 30d;
  67. add_header Cache-Control "public, max-age=2592000, immutable";
  68. # 如果不做这个配置,点击目录下的txt文件,大部分浏览器默认是直接浏览的。这里通过添加响应头来控制。
  69. if ($request_filename ~* ^.*?\.(html|txt|doc|pdf|rar|gz|zip|docx|exe|xlsx|ppt|pptx|conf)$){
  70. add_header Content-Disposition 'attachment;';
  71. }
  72. }
  73. #-------------------------------------------------
  74. # 课程管理
  75. #-------------------------------------------------
  76. location ^~ /course/ {
  77. alias /opt/course/;
  78. index index.html;
  79. # 安全头部配置
  80. add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload";
  81. add_header X-Content-Type-Options nosniff;
  82. add_header X-XSS-Protection "1; mode=block";
  83. add_header Referrer-Policy "same-origin";
  84. add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), interest-cohort=()";
  85. add_header Content-Security-Policy "default-src 'self'; worker-src 'self' blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; connect-src 'self' https:; font-src 'self' data: https:; frame-ancestors 'self'";
  86. try_files $uri $uri/ /course/index.html;
  87. }
  88. location = /course/api/device/status {
  89. # 允许所有域名跨域
  90. add_header 'Access-Control-Allow-Origin' '*';
  91. add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
  92. add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
  93. add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range';
  94. default_type application/json;
  95. content_by_lua_file /usr/local/openresty/lua/course_device_status.lua;
  96. }
  97. location ^~ /course/api/ {
  98. default_type application/json;
  99. add_header 'Access-Control-Allow-Origin' '*' always;
  100. add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS, PUT, DELETE' always;
  101. add_header 'Access-Control-Allow-Headers' 'Content-Type, Authorization, X-Requested-With' always;
  102. add_header 'Access-Control-Allow-Credentials' 'true' always;
  103. # 移除 rewrite,改用 proxy_pass 直接处理
  104. proxy_pass http://124.222.28.5:7213/;
  105. proxy_set_header Host m1.apifoxmock.com;
  106. proxy_set_header X-Real-IP $remote_addr;
  107. proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  108. proxy_set_header X-Forwarded-Proto $scheme;
  109. # 处理代理失败的情况(如404)
  110. proxy_intercept_errors on;
  111. error_page 404 = @course_api_fallback;
  112. }
  113. location @course_api_fallback {
  114. default_type application/json;
  115. content_by_lua_block {
  116. local uri = ngx.var.uri
  117. if uri:find("^/course/api/system/dict") then
  118. -- 字典相关接口
  119. local dict = require "course_dict"
  120. dict.handle(uri)
  121. else
  122. -- 其他接口走 mock
  123. local mock_router = require "course_mock"
  124. mock_router("/course/api")
  125. end
  126. }
  127. }
  128. #-------------------------------------------------
  129. # 健康检查
  130. #-------------------------------------------------
  131. location /health {
  132. access_log off;
  133. return 200 'healthy';
  134. add_header Content-Type text/plain;
  135. }
  136. #-------------------------------------------------
  137. # 错误页
  138. #-------------------------------------------------
  139. error_page 403 /403.html;
  140. error_page 404 /404.html;
  141. error_page 500 502 503 504 /50x.html;
  142. location = /403.html {
  143. }
  144. location = /404.html {
  145. }
  146. location = /50x.html {
  147. }
  148. #-------------------------------------------------
  149. # 安全配置
  150. #-------------------------------------------------
  151. # 安全配置:禁止访问隐藏文件
  152. location ~ /\. {
  153. deny all;
  154. access_log off;
  155. log_not_found off;
  156. }
  157. # 安全配置:禁止访问常见敏感文件
  158. location ~* (\.log|\.sql|\.env|\.git) {
  159. deny all;
  160. access_log off;
  161. log_not_found off;
  162. }
  163. }
  164. #=====================================================
  165. # HTTP -> HTTPS 自动跳转
  166. #=====================================================
  167. server {
  168. listen 80;
  169. server_name _;
  170. return 301 https://$host$request_uri;
  171. }