mirror of
https://github.com/suitenumerique/meet.git
synced 2026-07-26 20:08:24 +00:00
53722ad1bc
A previous CSP change suggested by CodeRabbit was not properly tested and broke inline styling as well as the loading of the ProConnect image. Adjust the CSP directives to allow these resources again.
86 lines
2.8 KiB
Plaintext
86 lines
2.8 KiB
Plaintext
server {
|
|
listen 8080;
|
|
server_name localhost;
|
|
server_tokens off;
|
|
|
|
root /usr/share/nginx/html;
|
|
|
|
location = /.well-known/windows-app-web-link {
|
|
default_type application/json;
|
|
alias /usr/share/nginx/html/.well-known/windows-app-web-link;
|
|
add_header Content-Disposition "attachment; filename=windows-app-web-link";
|
|
}
|
|
|
|
# Manifest — fetched, never iframed
|
|
location = /addons/outlook/manifest.xml {
|
|
alias /usr/share/nginx/html/addons/outlook/manifest.xml;
|
|
|
|
add_header Access-Control-Allow-Origin "*";
|
|
add_header Cache-Control "no-cache, no-store, must-revalidate";
|
|
add_header X-Frame-Options "DENY";
|
|
add_header Content-Security-Policy "frame-ancestors 'none'";
|
|
}
|
|
|
|
location = /addons/outlook/assets/ {
|
|
return 404;
|
|
}
|
|
|
|
location ~* ^/addons/outlook/assets/(.+\.(?:css|js|json|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot))/?$ {
|
|
root /usr/share/nginx/html;
|
|
expires 30d;
|
|
add_header Cache-Control "public, max-age=2592000, immutable" always;
|
|
add_header Access-Control-Allow-Origin "*";
|
|
add_header Vary "Origin" always;
|
|
}
|
|
|
|
location = /addons/outlook/ {
|
|
return 404;
|
|
}
|
|
|
|
location ~ ^/addons/outlook(/.*)?$ {
|
|
alias /usr/share/nginx/html/addons/outlook$1;
|
|
error_page 404 =200 /index.html;
|
|
add_header Cache-Control "no-cache, no-store, must-revalidate";
|
|
add_header Pragma "no-cache" always;
|
|
add_header Expires 0 always;
|
|
|
|
set $ms_domains "https://*.live.com https://*.office.com https://*.microsoft.com https://*.office365.com https://*.sharepoint.com";
|
|
|
|
set $nonce $request_id;
|
|
|
|
set $csp "default-src 'self'; upgrade-insecure-requests; ";
|
|
set $csp "${csp}frame-ancestors ${ms_domains}; ";
|
|
set $csp "${csp}script-src 'nonce-${nonce}' 'strict-dynamic'; ";
|
|
set $csp "${csp}style-src 'self' 'unsafe-inline'; ";
|
|
set $csp "${csp}img-src 'self' data:; ";
|
|
set $csp "${csp}font-src 'self' data:; ";
|
|
set $csp "${csp}connect-src 'self' ${ms_domains}; ";
|
|
set $csp "${csp}frame-src 'none'; ";
|
|
set $csp "${csp}object-src 'none'; ";
|
|
set $csp "${csp}base-uri 'none'; ";
|
|
|
|
add_header Content-Security-Policy $csp;
|
|
|
|
sub_filter 'NONCE_PLACEHOLDER' $nonce;
|
|
sub_filter_once off;
|
|
}
|
|
|
|
# Serve static files with caching
|
|
location ~* ^/assets/.*\.(css|js|json|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$ {
|
|
expires 30d;
|
|
add_header Cache-Control "public, max-age=2592000";
|
|
}
|
|
|
|
# Serve static files
|
|
location / {
|
|
try_files $uri $uri/ /index.html;
|
|
# Add no-cache headers
|
|
add_header Cache-Control "no-cache, no-store, must-revalidate";
|
|
add_header Pragma "no-cache"; # HTTP 1.0 header for backward compatibility
|
|
add_header Expires 0;
|
|
}
|
|
|
|
# Optionally, handle 404 errors by redirecting to index.html
|
|
error_page 404 =200 /index.html;
|
|
}
|