dorfteich/apps/web/nginx.conf
Claude Fable 5 75ec7f6006 CSP: data:-Fonts erlauben (eingebettete Fonts in Excalidraw-SVGs)
Excalidraw bettet beim Speichern die verwendeten Schrift-Subsets als
data:-URIs ins Snapshot-SVG ein. Die Seiten-CSP (nginx) und die
Plugin-Frame-CSP erlaubten aber nur `font-src 'self'` bzw. den
Asset-Pfad — die Handschrift fiel in der öffentlichen Ansicht und im
Snapshot-Render auf Serifen zurück (auf Prod an der ersten Demo-Skizze
sichtbar). Fix: `data:` in beiden font-src-Direktiven. data:-Fonts
lösen keinerlei Netzwerk-Request aus — die Zero-Third-Party-Garantie
(security.md) bleibt unberührt; fonts.ts-Kommentar entsprechend
präzisiert.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0155v2aT8AG1kZDQEZiCLBWC
2026-07-19 22:27:17 +02:00

40 lines
1.8 KiB
Nginx Configuration File

# SPA serving: static assets with long-lived caching, everything else
# falls back to index.html (client-side routing).
server {
listen 8080;
server_name _;
root /usr/share/nginx/html;
index index.html;
gzip on;
gzip_types text/css application/javascript application/json image/svg+xml;
gzip_min_length 1024;
location /healthz {
add_header Content-Type text/plain;
return 200 'ok';
}
location /assets/ {
# Vite emits content-hashed filenames — safe to cache forever.
add_header Cache-Control "public, max-age=31536000, immutable";
try_files $uri =404;
}
location / {
add_header Cache-Control "no-cache";
# Strict CSP (security.md, ADR 0016): everything self-hosted, zero
# third-party origins — fonts, scripts, styles, and XHR/WebSocket all
# from this origin only (the GDPR "zero external requests" posture).
# `style-src 'unsafe-inline'` covers the app's inline style attributes
# (CSS custom properties, layout); scripts are all external files.
# font-src includes `data:` for the subsetted fonts Excalidraw embeds
# into saved sketch SVGs (inlined by the plugin fallback renderer on
# public pages). data: fonts trigger no network request, so the
# zero-third-party-request guarantee (security.md) is unaffected.
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' data: blob:; connect-src 'self'; worker-src 'self'; manifest-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'" always;
add_header X-Content-Type-Options "nosniff" always;
try_files $uri /index.html;
}
}