summaryrefslogtreecommitdiff
path: root/nginx.conf
diff options
context:
space:
mode:
authorCaptainJack2491 <jayrupnakawala@gmail.com>2026-09-02 11:00:42 +0100
committerCaptainJack2491 <jayrupnakawala@gmail.com>2026-09-02 11:00:42 +0100
commit0ee667ac6cb2493e4f9ddaa5b69f595071aca936 (patch)
tree9051ebe3279544efe4ba228aa311b6bf41d4f7d3 /nginx.conf
parente7dc4befde5bef83d198a631926174bae612f866 (diff)
fix: title frontmatter, terminal resume, project list sync, nginx hardening, and stylesfixes/titles-nav-typos
Diffstat (limited to 'nginx.conf')
-rw-r--r--nginx.conf39
1 files changed, 32 insertions, 7 deletions
diff --git a/nginx.conf b/nginx.conf
index d4517f5..bae90e3 100644
--- a/nginx.conf
+++ b/nginx.conf
@@ -17,6 +17,32 @@ server {
# Don't leak nginx version on error pages / server header
server_tokens off;
+ # Gzip compression
+ gzip on;
+ gzip_vary on;
+ gzip_min_length 1024;
+ gzip_proxied any;
+ gzip_types text/plain text/css text/xml application/json application/javascript application/xml+rss image/svg+xml;
+
+ # Security headers
+ add_header X-Content-Type-Options "nosniff" always;
+ add_header X-Frame-Options "SAMEORIGIN" always;
+ add_header Referrer-Policy "strict-origin-when-cross-origin" always;
+
+ # Static asset caching
+ location ~* \.(ico|css|js|gif|jpe?g|png|svg|woff2?)$ {
+ expires 30d;
+ add_header Cache-Control "public, no-transform";
+ }
+
+ # Compatibility for assets prefix
+ location = /assets/public_key {
+ try_files /public_key /assets/public_key =404;
+ }
+ location = /assets/dissertation.pdf {
+ try_files /dissertation.pdf /assets/dissertation.pdf =404;
+ }
+
# Serve PDFs directly
location ~* \.pdf$ {
add_header Content-Type application/pdf;
@@ -24,13 +50,13 @@ server {
try_files $uri =404;
}
- # /cv should point to the PDF
+ # /cv should point to the PDF or plaintext cv
location = /cv {
- try_files
- /cv$final_suffix
- /cv/index$final_suffix
- /cv.pdf
- =404;
+ try_files
+ /cv$final_suffix
+ /cv/index$final_suffix
+ /cv.pdf
+ =404;
}
# /dissertation serves summary page or PDF fallback
@@ -43,7 +69,6 @@ server {
=404;
}
-
location / {
try_files
$uri$final_suffix