# Nginx

This page covers the routing blocks, caching, and security headers in `config/nginx/nodejs.conf`, and how to restrict upload and delete by source IP.

## Routing Blocks

| `location` | Upstream | Behavior |
|---|---|---|
| `~ /\.` | — | `deny all`; rejects any path containing `/.` (including `.trash`) |
| `~* ^/c/img/` | `http://nodejs:8080` | `proxy_cache` enabled, 120-second timeouts |
| `~* ^/upload/` | `http://nodejs:3000` | `proxy_no_cache 1`, `proxy_cache_bypass 1` |
| `~* ^/del/` | `http://nodejs:3000` | Not cached |
| `/` | `http://nodejs:3000` | Not cached |

## Caching

| Directive | Value |
|---|---|
| `proxy_cache_path` | `/var/cache/nginx/images`, `levels=1:2`, `keys_zone=images_cache:10m`, `max_size=2g`, `inactive=30d` |
| `proxy_cache_valid` | `200 302 301 304` for 7 days, everything else 1 minute |
| `proxy_cache_use_stale` | `error timeout updating http_500 http_502 http_503 http_504` |
| `proxy_cache_lock`, `proxy_cache_revalidate`, `proxy_cache_background_update` | `on` |
| Response headers | `X-Cache-Status`, `Cache-Control: public, max-age=604800`, `expires 7d` |
| gzip | `image/webp image/jpeg image/png image/svg+xml image/avif application/pdf`, level 6, minimum 1000 bytes |

```bash
# Check cache status (HIT / MISS / EXPIRED)
curl -sI "http://localhost:8080/c/img/blog/a.jpg?w=800" | grep -i x-cache-status
```

## Security Settings

| Setting | Value |
|---|---|
| `server_tokens` | `off`, plus `proxy_hide_header` for `X-Powered-By` and other framework headers |
| HTTP methods | Anything other than `GET HEAD POST DELETE PUT OPTIONS` returns `444` |
| Upload size | `client_max_body_size 100M` |
| `server`-level headers | `X-Content-Type-Options`, `X-Frame-Options`, `X-XSS-Protection`, `Referrer-Policy`, `Permissions-Policy`, `Content-Security-Policy` |

## Restrict Upload and Delete

The `/upload/` and `/del/` blocks already contain commented lines; uncomment them and use your own internal network:

```nginx
location ~* ^/upload/ {
    allow 10.0.0.0/8;
    deny all;

    proxy_pass http://nodejs:8080;
    # ...
}
```

Reload after editing:

```bash
docker compose exec nginx nginx -s reload
```
