Excalidraw bettet beim Speichern die verwendeten Schrift-Subsets als data:-URIs ins Snapshot-SVG ein. Die Seiten-CSP (nginx) und die Plugin-Frame-CSP erlaubten aber nur `font-src 'self'` bzw. den Asset-Pfad — die Handschrift fiel in der öffentlichen Ansicht und im Snapshot-Render auf Serifen zurück (auf Prod an der ersten Demo-Skizze sichtbar). Fix: `data:` in beiden font-src-Direktiven. data:-Fonts lösen keinerlei Netzwerk-Request aus — die Zero-Third-Party-Garantie (security.md) bleibt unberührt; fonts.ts-Kommentar entsprechend präzisiert. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0155v2aT8AG1kZDQEZiCLBWC
40 lines
1.8 KiB
Nginx Configuration File
40 lines
1.8 KiB
Nginx Configuration File
# SPA serving: static assets with long-lived caching, everything else
|
|
# falls back to index.html (client-side routing).
|
|
server {
|
|
listen 8080;
|
|
server_name _;
|
|
root /usr/share/nginx/html;
|
|
index index.html;
|
|
|
|
gzip on;
|
|
gzip_types text/css application/javascript application/json image/svg+xml;
|
|
gzip_min_length 1024;
|
|
|
|
location /healthz {
|
|
add_header Content-Type text/plain;
|
|
return 200 'ok';
|
|
}
|
|
|
|
location /assets/ {
|
|
# Vite emits content-hashed filenames — safe to cache forever.
|
|
add_header Cache-Control "public, max-age=31536000, immutable";
|
|
try_files $uri =404;
|
|
}
|
|
|
|
location / {
|
|
add_header Cache-Control "no-cache";
|
|
# Strict CSP (security.md, ADR 0016): everything self-hosted, zero
|
|
# third-party origins — fonts, scripts, styles, and XHR/WebSocket all
|
|
# from this origin only (the GDPR "zero external requests" posture).
|
|
# `style-src 'unsafe-inline'` covers the app's inline style attributes
|
|
# (CSS custom properties, layout); scripts are all external files.
|
|
# font-src includes `data:` for the subsetted fonts Excalidraw embeds
|
|
# into saved sketch SVGs (inlined by the plugin fallback renderer on
|
|
# public pages). data: fonts trigger no network request, so the
|
|
# zero-third-party-request guarantee (security.md) is unaffected.
|
|
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; font-src 'self' data:; img-src 'self' data: blob:; connect-src 'self'; worker-src 'self'; manifest-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'" always;
|
|
add_header X-Content-Type-Options "nosniff" always;
|
|
try_files $uri /index.html;
|
|
}
|
|
}
|