mirror of
https://github.com/Shik3i/KoalaSync.git
synced 2026-08-09 02:39:38 +00:00
feat(website): implement Clean URLs and split Caddy configurations
- Removed all .html file extension suffixes from website and invite links (impressum, datenschutz, join).
- Updated app.js dynamic localizer and path switching to target Clean URLs ('./', '../', etc.).
- Refactored Caddyfile.example into simple (lightweight try_files) and advanced (hardened production) options.
- Split Caddy configs into Caddyfile (Simple) and Caddyfile (Advanced) tabs on the landing page.
This commit is contained in:
+56
-19
@@ -1,11 +1,44 @@
|
||||
# ==============================================================================
|
||||
# KoalaSync - Production Caddy Configuration Example
|
||||
# Replace domains and paths with your actual setup.
|
||||
# ==============================================================================
|
||||
# This file provides examples of both a lightweight "Simple" configuration
|
||||
# and a production-hardened "Advanced" configuration.
|
||||
# Replace domains, reverse proxy locations, and directories with your actual setup.
|
||||
|
||||
# ------------------------------------------------------------------------------
|
||||
# OPTION A: Simple Configuration
|
||||
# ------------------------------------------------------------------------------
|
||||
# Minimal configuration that serves the static website, enables gzip compression,
|
||||
# supports extension-less Clean URLs, and reverse proxies the relay server.
|
||||
|
||||
# sync.koalastuff.net {
|
||||
# root * /var/www/koalasync/website/www
|
||||
# encode zstd gzip
|
||||
#
|
||||
# # Clean URLs support (resolves /join to join.html, etc.)
|
||||
# try_files {path} {path}.html {path}/
|
||||
# file_server
|
||||
# }
|
||||
#
|
||||
# syncserver.koalastuff.net {
|
||||
# reverse_proxy localhost:3000
|
||||
# }
|
||||
|
||||
|
||||
# ------------------------------------------------------------------------------
|
||||
# OPTION B: Advanced Configuration (Production-Hardened)
|
||||
# ------------------------------------------------------------------------------
|
||||
# Highly secure, optimized configuration using advanced HTTP security headers,
|
||||
# aggressive static assets caching, server signature concealment, and strict
|
||||
# hardware permission access policies.
|
||||
|
||||
# 1. Marketing Website & Invitation Bridge
|
||||
sync.koalastuff.net {
|
||||
root * /var/www/koalasync/website/www
|
||||
file_server
|
||||
encode zstd gzip
|
||||
root * /var/www/koalasync/website/www
|
||||
|
||||
# Clean URLs: Resolves paths without .html in the URL
|
||||
try_files {path} {path}.html {path}/
|
||||
file_server
|
||||
|
||||
# Static Caching for high-performance PageSpeed (1 year with validation)
|
||||
@static {
|
||||
@@ -16,31 +49,35 @@ sync.koalastuff.net {
|
||||
|
||||
# Security Headers & Content Security Policy (CSP)
|
||||
header {
|
||||
# Strict Content Security Policy (restricts scripts and connections to self, forbids frames)
|
||||
Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self'; img-src 'self' data:; object-src 'none'; frame-ancestors 'none';"
|
||||
# Prevent FLoC tracking
|
||||
Permissions-Policy interest-cohort=()
|
||||
# Security best practices
|
||||
# CSP hardened with base-uri and form-action limits
|
||||
Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; connect-src 'self'; img-src 'self' data:; object-src 'none'; frame-ancestors 'none'; base-uri 'none'; form-action 'none';"
|
||||
|
||||
# Strict Transport Security (HSTS)
|
||||
Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
|
||||
X-Content-Type-Options nosniff
|
||||
X-Frame-Options DENY
|
||||
Referrer-Policy no-referrer-when-downgrade
|
||||
|
||||
# Security best practices
|
||||
X-Frame-Options "DENY"
|
||||
X-Content-Type-Options "nosniff"
|
||||
Referrer-Policy "strict-origin-when-cross-origin"
|
||||
|
||||
# Modern Permissions Policy (blocks browser hardware access for enhanced privacy)
|
||||
Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()"
|
||||
|
||||
# Remove Caddy's server stamp signature
|
||||
-Server
|
||||
}
|
||||
}
|
||||
|
||||
# 2. Relay Server (Socket.IO / WebSocket)
|
||||
syncserver.koalastuff.net {
|
||||
reverse_proxy localhost:3000 {
|
||||
# Ensure WebSocket support is explicitly handled if needed
|
||||
# (Caddy usually handles this automatically)
|
||||
header_up Host {host}
|
||||
header_up X-Real-IP {remote_host}
|
||||
}
|
||||
|
||||
# Security Headers for the relay
|
||||
header {
|
||||
X-Content-Type-Options nosniff
|
||||
X-Frame-Options DENY
|
||||
Referrer-Policy no-referrer
|
||||
X-Content-Type-Options "nosniff"
|
||||
X-Frame-Options "DENY"
|
||||
Referrer-Policy "strict-origin-when-cross-origin"
|
||||
-Server
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user