# 内部纯 HTTP 静态资源服务片段(无 TLS,监听 3000) # # 现状说明(2026-09-23 配置核对):本文件的唯一使用者是已删除的 Dockerfile.static # (它 COPY 一个不存在的 html/ 目录,standalone 产物下无从产生)。保留仅为「同机内网 # 只跑静态资源」的可选形态;若下一轮配置审计确认无人使用即可删除,删除前需同步 docs。 # # 头部分工:文档级安全头(CSP / X-Frame-Options / X-Content-Type-Options / Referrer-Policy / # Permissions-Policy / X-XSS-Protection)唯一来源为 next.config.mjs 的 headers(), # 此处不再 add_header 同名头部——本片段若直服页面 HTML,页面会缺头;因此本片段 # 只服务不可变静态资源,页面一律交给 Next standalone 运行时(见 nginx-static.conf)。 server { listen 3000; server_name localhost; root /var/www/novalon; index index.html; gzip on; gzip_vary on; gzip_proxied any; gzip_comp_level 6; gzip_min_length 256; gzip_types text/plain text/css text/xml text/javascript application/json application/javascript application/xml application/rss+xml image/svg+xml; # 原此处 add_header X-Frame-Options / X-XSS-Protection / X-Content-Type-Options: # 与 next.config.mjs 同名,已删除(详见该文件的分工注释)。 location /_next/static/ { expires 1y; add_header Cache-Control "public, max-age=31536000, immutable"; try_files $uri =404; } location /fonts/ { expires 1y; add_header Cache-Control "public, max-age=31536000, immutable"; add_header Access-Control-Allow-Origin "*"; try_files $uri =404; } location ~* \.(svg|jpg|jpeg|png|gif|webp|avif|ico)$ { expires 1y; add_header Cache-Control "public, max-age=31536000, immutable"; try_files $uri =404; } # 本片段只服务不可变静态资源:页面 HTML 必须由 Next standalone 应答(安全头随 # next.config.mjs 一起发出)。原 `try_files $uri $uri.html $uri/ /404.html` 是静态导出 # 时代的残留——在这里直服 HTML 会让页面一个安全头都没有。 location / { return 404; } # 不设 error_page /404.html:页面 404 属应用职责,见上。 sendfile on; tcp_nopush on; tcp_nodelay on; keepalive_timeout 65; }