mirror of
https://github.com/Wei-Shaw/sub2api.git
synced 2026-09-24 16:05:44 +08:00
fix(web): limit immutable caching to fingerprinted assets
This commit is contained in:
@@ -1,21 +1,5 @@
|
||||
# 修改为你的域名
|
||||
api.sub2api.com {
|
||||
# =========================================================================
|
||||
# 静态资源长期缓存(高优先级,放在最前面)
|
||||
# 带 hash 的文件可以永久缓存,浏览器和 CDN 都会缓存
|
||||
# =========================================================================
|
||||
@static {
|
||||
path /assets/*
|
||||
path /logo.png
|
||||
path /favicon.ico
|
||||
}
|
||||
header @static {
|
||||
Cache-Control "public, max-age=31536000, immutable"
|
||||
# 移除可能干扰缓存的头
|
||||
-Pragma
|
||||
-Expires
|
||||
}
|
||||
|
||||
# =========================================================================
|
||||
# TLS 安全配置
|
||||
# =========================================================================
|
||||
|
||||
Executable
+18
@@ -0,0 +1,18 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
repo_root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
|
||||
caddyfile="$repo_root/deploy/Caddyfile"
|
||||
active_config=$(sed 's/[[:space:]]*#.*$//' "$caddyfile")
|
||||
|
||||
if printf '%s\n' "$active_config" | grep -Eiq 'Cache-Control.*immutable'; then
|
||||
echo "Caddyfile must not force immutable caching; the backend owns asset cache policy" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if ! printf '%s\n' "$active_config" | grep -Eq '^[[:space:]]*reverse_proxy[[:space:]]+localhost:8080'; then
|
||||
echo "Caddyfile must continue proxying all application routes to localhost:8080" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "Caddyfile preserves backend Cache-Control policy and reverse_proxy routing"
|
||||
Reference in New Issue
Block a user