release(main): 同步 dev 最新候选改动
Storage Persistence Guard / storage-persistence-audit (push) Has been cancelled
Client Quality Gates / Shared client and Web (push) Has been cancelled
Client Quality Gates / macOS Desktop (push) Has been cancelled
Client Quality Gates / Shared client and Web (pull_request) Has been cancelled
Client Quality Gates / macOS Desktop (pull_request) Has been cancelled
Storage Persistence Guard / storage-persistence-audit (pull_request) Has been cancelled

This commit is contained in:
Cheng Zhou
2026-07-16 17:15:50 +08:00
parent 32167fba02
commit d5279b124f
393 changed files with 51630 additions and 9711 deletions
+53 -1
View File
@@ -28,10 +28,30 @@ http {
server backend:8000 resolve;
}
upstream onlyoffice {
zone onlyoffice 64k;
server onlyoffice:80 resolve;
}
map $http_upgrade $connection_upgrade {
default upgrade;
"" close;
}
map $http_x_forwarded_proto $onlyoffice_scheme {
default $http_x_forwarded_proto;
"" $scheme;
}
map $http_x_forwarded_host $onlyoffice_host {
default $http_x_forwarded_host;
"" $http_host;
}
server {
listen 80;
server_name _;
client_max_body_size 20m;
client_max_body_size 50m;
location = /favicon.ico {
root /usr/share/nginx/html;
@@ -47,6 +67,17 @@ http {
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
}
location = /onlyoffice-host.html {
try_files /onlyoffice-host.html =404;
add_header Cache-Control "no-store" always;
add_header Content-Security-Policy "default-src 'none'; script-src 'self'; connect-src 'self'; img-src 'self' data: blob:; style-src 'self' 'unsafe-inline'; frame-src 'self' blob:; frame-ancestors 'self' tauri: http://tauri.localhost https://tauri.localhost http://localhost:* http://127.0.0.1:*; object-src 'none'; base-uri 'none'; form-action 'none'" always;
}
location = /onlyoffice-host.js {
try_files /onlyoffice-host.js =404;
add_header Cache-Control "no-store" always;
}
location /assets/ {
try_files $uri =404;
add_header Cache-Control "public, max-age=31536000, immutable" always;
@@ -66,6 +97,19 @@ http {
proxy_set_header X-Forwarded-Proto $scheme;
}
location /onlyoffice/ {
proxy_pass http://onlyoffice/;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_set_header Host $http_host;
proxy_set_header X-Forwarded-Host $onlyoffice_host/onlyoffice;
proxy_set_header X-Forwarded-Proto $onlyoffice_scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 3600s;
proxy_send_timeout 3600s;
}
location /health {
proxy_pass http://backend;
proxy_set_header Host $host;
@@ -74,6 +118,14 @@ http {
proxy_set_header X-Forwarded-Proto $scheme;
}
location = /readyz {
proxy_pass http://backend;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location / {
try_files $uri $uri/ /index.html;
add_header Cache-Control "no-store, no-cache, must-revalidate" always;