diff --git a/deploy/nginx-dashboards-ssl.conf b/deploy/nginx-dashboards-ssl.conf index dde8bc3..7523327 100644 --- a/deploy/nginx-dashboards-ssl.conf +++ b/deploy/nginx-dashboards-ssl.conf @@ -2,11 +2,12 @@ # # Link-preview bots (WhatsApp, etc.) hitting /invoices/:id get Open Graph HTML # from the API; browsers still receive the SPA. - -map $http_user_agent $meshkee_link_preview_bot { - default 0; - ~*(whatsapp|facebookexternalhit|facebot|twitterbot|linkedinbot|slackbot|telegrambot|discordbot) 1; -} +# +# Install the UA map in http context (e.g. /etc/nginx/conf.d/meshkee-link-preview-bots.conf): +# map $http_user_agent $meshkee_link_preview_bot { +# default 0; +# ~*(whatsapp|facebookexternalhit|facebot|twitterbot|linkedinbot|slackbot|telegrambot|discordbot) 1; +# } server { listen 443 ssl; @@ -15,7 +16,8 @@ server { ssl_certificate_key /etc/letsencrypt/live/meshkee-dashboards/privkey.pem; ssl_protocols TLSv1.2 TLSv1.3; - location ~ ^/invoices/(?[0-9]{6,32})$ { + # Quotes required: unquoted {N,M} breaks nginx config parsing. + location ~ "^/invoices/(?[0-9]{6,32})$" { if ($meshkee_link_preview_bot = 1) { rewrite ^ /__internal/invoice-og/$invoice_public_id last; } @@ -23,9 +25,11 @@ server { try_files /index.html =404; } - location ~ ^/__internal/invoice-og/([0-9]{6,32})$ { + location ~ "^/__internal/invoice-og/([0-9]{6,32})$" { internal; - proxy_pass https://api.meshkee.com/api/v1/public/invoices/$1/og; + # rewrite+break keeps proxy_pass host static (no runtime resolver needed) + rewrite ^/__internal/invoice-og/(.*)$ /api/v1/public/invoices/$1/og break; + proxy_pass https://api.meshkee.com; proxy_ssl_server_name on; proxy_set_header Host api.meshkee.com; proxy_set_header X-Real-IP $remote_addr;