443.conf 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118
  1. server {
  2. listen 443 ssl;
  3. http2 on;
  4. server_name _;
  5. # SSL证书路径
  6. ssl_certificate /usr/local/openresty/nginx/ssl/ali.haijunit.icu.pem;
  7. ssl_certificate_key /usr/local/openresty/nginx/ssl/ali.haijunit.icu.key;
  8. ssl_protocols TLSv1.2 TLSv1.3;
  9. ssl_ciphers 'EECDH+AESGCM:EECDH+CHACHA20:EECDH+AES256:!aNULL:!MD5:!RC4';
  10. ssl_prefer_server_ciphers on;
  11. ssl_session_cache shared:SSL:50m;
  12. ssl_session_timeout 10m;
  13. ssl_stapling on;
  14. ssl_stapling_verify on;
  15. # 可选:显式指定 TLSv1.3 cipher(仅 OpenSSL 1.1.1+ 支持)
  16. ssl_conf_command Ciphersuites TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256;
  17. # 安全 Header
  18. add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
  19. add_header X-Frame-Options SAMEORIGIN;
  20. add_header X-Content-Type-Options nosniff;
  21. add_header X-XSS-Protection "1; mode=block";
  22. add_header Content-Security-Policy "default-src 'self' data: blob: https:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' data: https:;" always;
  23. root html;
  24. try_files $uri $uri/ /index.html;
  25. #-------------------------------------------------
  26. # 通用业务
  27. #-------------------------------------------------
  28. location = / {
  29. rewrite ^/ /course break;
  30. }
  31. #-------------------------------------------------
  32. # 前端应用
  33. #-------------------------------------------------
  34. location / {
  35. index index.html;
  36. try_files $uri $uri/ /index.html;
  37. expires 7d;
  38. add_header Cache-Control "public, max-age=604800, immutable";
  39. }
  40. #-------------------------------------------------
  41. # 静态资源缓存 + 防盗链
  42. #-------------------------------------------------
  43. location ~* \.(js|css|png|jpg|jpeg|gif|svg|woff2?|ttf|ico)$ {
  44. expires 30d;
  45. access_log off;
  46. add_header Cache-Control "public, max-age=2592000, immutable";
  47. }
  48. #-------------------------------------------------
  49. # 课程管理
  50. #-------------------------------------------------
  51. location ^~ /course/ {
  52. default_type application/json;
  53. add_header 'Access-Control-Allow-Origin' '*';
  54. add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS';
  55. add_header 'Access-Control-Allow-Headers' 'DNT,User-Agent,X-Requested-With,If-Modified-Since,Cache-Control,Content-Type,Range';
  56. add_header 'Access-Control-Expose-Headers' 'Content-Length,Content-Range';
  57. # 移除 rewrite,改用 proxy_pass 直接处理
  58. proxy_pass http://127.0.0.1:8082/;
  59. }
  60. #-------------------------------------------------
  61. # 健康检查
  62. #-------------------------------------------------
  63. location /health {
  64. access_log off;
  65. return 200 'healthy';
  66. add_header Content-Type text/plain;
  67. }
  68. #-------------------------------------------------
  69. # 错误页
  70. #-------------------------------------------------
  71. error_page 403 /403.html;
  72. error_page 404 /404.html;
  73. error_page 500 502 503 504 /50x.html;
  74. location = /403.html {
  75. }
  76. location = /404.html {
  77. }
  78. location = /50x.html {
  79. }
  80. #-------------------------------------------------
  81. # 安全配置
  82. #-------------------------------------------------
  83. # 安全配置:禁止访问隐藏文件
  84. location ~ /\. {
  85. deny all;
  86. access_log off;
  87. log_not_found off;
  88. }
  89. # 安全配置:禁止访问常见敏感文件
  90. location ~* (\.log|\.sql|\.env|\.git) {
  91. deny all;
  92. access_log off;
  93. log_not_found off;
  94. }
  95. }
  96. #=====================================================
  97. # HTTP -> HTTPS 自动跳转
  98. #=====================================================
  99. server {
  100. listen 80;
  101. server_name _;
  102. return 301 https://$host$request_uri;
  103. }