- Remove dead kitchen->KDS internal API (api/internal.py, verify_internal_secret) — KDS reads kitchen_db directly (E16), nothing ever called this endpoint - Add expires_at to dispute_attachments; public attachment links now expire after 30 days instead of staying valid forever (A4) - Add services/upload_validation.py: sniff real file content via python-magic instead of trusting the client-supplied Content-Type header, plus a 20MB cap. Applied across invoices/logbook/food_flags/credit_notes/disputes upload endpoints (A5) — disputes previously had no file-type check at all - Fix nginx client_max_body_size drift (800m -> the plan's intended 20m) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
53 lines
1.3 KiB
Nginx Configuration File
53 lines
1.3 KiB
Nginx Configuration File
types {
|
|
text/javascript js mjs;
|
|
application/pdf pdf;
|
|
}
|
|
|
|
server {
|
|
listen 80;
|
|
server_name _;
|
|
|
|
# Block internal inter-app endpoints from public access
|
|
location /kitchen/api/internal/ {
|
|
return 403;
|
|
}
|
|
|
|
# Central auth proxy — must be before the general /api/ block
|
|
location /kitchen/api/auth/ {
|
|
proxy_pass http://10.10.10.101:3001/api/auth/;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
}
|
|
|
|
# App backend (FastAPI on port 8000)
|
|
# /kitchen/api/foo → backend:8000/api/foo (prefix preserved)
|
|
location /kitchen/api/ {
|
|
proxy_pass http://backend:8000/api/;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
|
proxy_set_header Cookie $http_cookie;
|
|
proxy_read_timeout 600s;
|
|
proxy_connect_timeout 30s;
|
|
client_max_body_size 20m;
|
|
}
|
|
|
|
# Health
|
|
location /kitchen/health {
|
|
proxy_pass http://backend:8000/health;
|
|
}
|
|
|
|
# Static assets — long cache
|
|
location ~* /kitchen/assets/ {
|
|
root /usr/share/nginx/html;
|
|
expires 1y;
|
|
add_header Cache-Control "public, immutable";
|
|
}
|
|
|
|
# SPA fallback
|
|
location /kitchen/ {
|
|
root /usr/share/nginx/html;
|
|
try_files $uri $uri/ /kitchen/index.html;
|
|
}
|
|
}
|