chore(qa): 验收台账与证据入库 + 构建/部署配置同步
- docs/acceptance/qa-tracker.md:跨周期缺陷单一真源台账(§7=第五轮)。 - 周期 1/2 + iPhone SE/axe 验收证据目录、ACCEPTANCE_REVIEW 快照入库。 - 同步 README/CONTEXT/CLAUDE/DESIGN/testing/deployment/lessons-learned 口径; next.config/Dockerfile/nginx/Jenkinsfile/docker-compose/sentry/prisma 对齐 standalone 产物装配与部署形态。
This commit is contained in:
+17
-5
@@ -1,3 +1,13 @@
|
||||
# 内部纯 HTTP 静态资源服务片段(无 TLS,监听 3000)
|
||||
#
|
||||
# 现状说明(2026-09-23 配置核对):本文件的唯一使用者是已删除的 Dockerfile.static
|
||||
# (它 COPY 一个不存在的 html/ 目录,standalone 产物下无从产生)。保留仅为「同机内网
|
||||
# 只跑静态资源」的可选形态;若下一轮配置审计确认无人使用即可删除,删除前需同步 docs。
|
||||
#
|
||||
# 头部分工:文档级安全头(CSP / X-Frame-Options / X-Content-Type-Options / Referrer-Policy /
|
||||
# Permissions-Policy / X-XSS-Protection)唯一来源为 next.config.mjs 的 headers(),
|
||||
# 此处不再 add_header 同名头部——本片段若直服页面 HTML,页面会缺头;因此本片段
|
||||
# 只服务不可变静态资源,页面一律交给 Next standalone 运行时(见 nginx-static.conf)。
|
||||
server {
|
||||
listen 3000;
|
||||
server_name localhost;
|
||||
@@ -21,9 +31,8 @@ server {
|
||||
application/rss+xml
|
||||
image/svg+xml;
|
||||
|
||||
add_header X-Frame-Options "SAMEORIGIN" always;
|
||||
add_header X-XSS-Protection "1; mode=block" always;
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
# 原此处 add_header X-Frame-Options / X-XSS-Protection / X-Content-Type-Options:
|
||||
# 与 next.config.mjs 同名,已删除(详见该文件的分工注释)。
|
||||
|
||||
location /_next/static/ {
|
||||
expires 1y;
|
||||
@@ -44,11 +53,14 @@ server {
|
||||
try_files $uri =404;
|
||||
}
|
||||
|
||||
# 本片段只服务不可变静态资源:页面 HTML 必须由 Next standalone 应答(安全头随
|
||||
# next.config.mjs 一起发出)。原 `try_files $uri $uri.html $uri/ /404.html` 是静态导出
|
||||
# 时代的残留——在这里直服 HTML 会让页面一个安全头都没有。
|
||||
location / {
|
||||
try_files $uri $uri.html $uri/ /404.html;
|
||||
return 404;
|
||||
}
|
||||
|
||||
error_page 404 /404.html;
|
||||
# 不设 error_page /404.html:页面 404 属应用职责,见上。
|
||||
|
||||
sendfile on;
|
||||
tcp_nopush on;
|
||||
|
||||
Reference in New Issue
Block a user