diff --git a/docker/nginx.conf.template b/docker/nginx.conf.template index 291b5c6c..61e7ad3e 100644 --- a/docker/nginx.conf.template +++ b/docker/nginx.conf.template @@ -34,6 +34,21 @@ server { proxy_read_timeout 3600s; } + location = /index.html { + add_header Cache-Control "no-store, no-cache, must-revalidate" always; + try_files $uri =404; + } + + location = /config.js { + add_header Cache-Control "no-store, no-cache, must-revalidate" always; + try_files $uri =404; + } + + location ~* \.(js|css)$ { + add_header Cache-Control "public, max-age=31536000, immutable" always; + try_files $uri =404; + } + location / { try_files $uri $uri/ /index.html; } diff --git a/docker/smoke/frontend-policy-smoke.sh b/docker/smoke/frontend-policy-smoke.sh index 2c3d5d1f..e2c9665f 100755 --- a/docker/smoke/frontend-policy-smoke.sh +++ b/docker/smoke/frontend-policy-smoke.sh @@ -16,6 +16,35 @@ for setting in \ fi done +for location in \ + 'location = /index.html {' \ + 'location = /config.js {'; do + if ! grep -Fq "$location" "$nginx_config"; then + echo "missing exact frontend cache location: $location" >&2 + exit 1 + fi +done + +if ! grep -Fq 'location ~* \.(js|css)$ {' "$nginx_config"; then + echo "missing frontend JS/CSS asset cache location" >&2 + exit 1 +fi + +if [ "$(grep -Fc 'add_header Cache-Control "no-store, no-cache, must-revalidate" always;' "$nginx_config")" -lt 2 ]; then + echo "frontend index/config locations must disable caching" >&2 + exit 1 +fi + +if ! grep -Fq 'add_header Cache-Control "public, max-age=31536000, immutable" always;' "$nginx_config"; then + echo "frontend JS/CSS assets must use immutable long-lived caching" >&2 + exit 1 +fi + +if [ "$(grep -Fc 'try_files $uri =404;' "$nginx_config")" -lt 2 ]; then + echo "frontend config/assets must fail with 404 instead of falling back to the SPA" >&2 + exit 1 +fi + if ! grep -Fqx 'THT_FRONTEND_API_UPSTREAM=${THT_FRONTEND_API_UPSTREAM:-http://core:8787}' \ docker/frontend-entrypoint.sh; then echo "frontend entrypoint is missing the private core default" >&2