# App — NGINX (seul, sans Apache) # Sert les fichiers statiques + reverse proxy vers FastAPI # # Installation : # sudo cp deploy/nginx-app.conf /etc/nginx/sites-available/app # sudo ln -s /etc/nginx/sites-available/app /etc/nginx/sites-enabled/ # sudo nginx -t && sudo systemctl reload nginx # sudo certbot --nginx -d app.87-16.org server { listen 80; server_name app.87-16.org; # ── Headers de sécurité ── add_header X-Content-Type-Options nosniff always; add_header X-Frame-Options DENY always; add_header X-XSS-Protection "1; mode=block" always; add_header Referrer-Policy strict-origin-when-cross-origin always; # ── Backend API → FastAPI (Uvicorn sur port 8000) ── location /api/ { proxy_pass http://127.0.0.1:8000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; # Rate limiting anti-brute force (PIN) # Décommenter après avoir ajouté dans nginx.conf section http : # limit_req_zone $binary_remote_addr zone=api_limit:10m rate=5r/s; # limit_req zone=api_limit burst=10 nodelay; } # ── Frontend — fichiers statiques (React build) ── root /var/www/app; index index.html; # Cache longue durée sur les assets (JS, CSS, images) location ~* \.(js|css|png|jpg|svg|woff2|ico)$ { expires 1y; add_header Cache-Control "public, immutable"; try_files $uri =404; } # SPA routing : toute route qui n'est pas un fichier → index.html location / { try_files $uri $uri/ /index.html; } # Pas de cache sur index.html (pour que les mises à jour PWA passent) location = /index.html { add_header Cache-Control "no-cache, no-store, must-revalidate"; } client_max_body_size 5M; }