fix(web): limit immutable caching to fingerprinted assets

This commit is contained in:
王鹏
2026-07-15 04:00:46 +08:00
parent da85cc7e47
commit 60bae26a2f
6 changed files with 128 additions and 52 deletions
-16
View File
@@ -1,21 +1,5 @@
# 修改为你的域名
api.sub2api.com {
# =========================================================================
# 静态资源长期缓存(高优先级,放在最前面)
# 带 hash 的文件可以永久缓存,浏览器和 CDN 都会缓存
# =========================================================================
@static {
path /assets/*
path /logo.png
path /favicon.ico
}
header @static {
Cache-Control "public, max-age=31536000, immutable"
# 移除可能干扰缓存的头
-Pragma
-Expires
}
# =========================================================================
# TLS 安全配置
# =========================================================================
+18
View File
@@ -0,0 +1,18 @@
#!/bin/sh
set -eu
repo_root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)
caddyfile="$repo_root/deploy/Caddyfile"
active_config=$(sed 's/[[:space:]]*#.*$//' "$caddyfile")
if printf '%s\n' "$active_config" | grep -Eiq 'Cache-Control.*immutable'; then
echo "Caddyfile must not force immutable caching; the backend owns asset cache policy" >&2
exit 1
fi
if ! printf '%s\n' "$active_config" | grep -Eq '^[[:space:]]*reverse_proxy[[:space:]]+localhost:8080'; then
echo "Caddyfile must continue proxying all application routes to localhost:8080" >&2
exit 1
fi
echo "Caddyfile preserves backend Cache-Control policy and reverse_proxy routing"