Files
dashboards/deploy/nginx-dashboards-ssl.conf
T
Alireza HassaniandCursor 9e5a03548f Fix dashboard nginx Open Graph bot routing for invoice URLs.
Quote regex braces and proxy via rewrite so api.meshkee.com resolves without a runtime DNS resolver.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-11 16:21:12 +03:30

92 lines
3.0 KiB
Plaintext

# HTTPS dashboards (Certbot SANs on meshkee-dashboards)
#
# Link-preview bots (WhatsApp, etc.) hitting /invoices/:id get Open Graph HTML
# from the API; browsers still receive the SPA.
#
# Install the UA map in http context (e.g. /etc/nginx/conf.d/meshkee-link-preview-bots.conf):
# map $http_user_agent $meshkee_link_preview_bot {
# default 0;
# ~*(whatsapp|facebookexternalhit|facebot|twitterbot|linkedinbot|slackbot|telegrambot|discordbot) 1;
# }
server {
listen 443 ssl;
server_name manage.meshkee.com;
ssl_certificate /etc/letsencrypt/live/meshkee-dashboards/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/meshkee-dashboards/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
# Quotes required: unquoted {N,M} breaks nginx config parsing.
location ~ "^/invoices/(?<invoice_public_id>[0-9]{6,32})$" {
if ($meshkee_link_preview_bot = 1) {
rewrite ^ /__internal/invoice-og/$invoice_public_id last;
}
root /var/www/meshkee/super-admin;
try_files /index.html =404;
}
location ~ "^/__internal/invoice-og/([0-9]{6,32})$" {
internal;
# rewrite+break keeps proxy_pass host static (no runtime resolver needed)
rewrite ^/__internal/invoice-og/(.*)$ /api/v1/public/invoices/$1/og break;
proxy_pass https://api.meshkee.com;
proxy_ssl_server_name on;
proxy_set_header Host api.meshkee.com;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location / {
root /var/www/meshkee/super-admin;
try_files $uri $uri/ /index.html;
}
}
server {
listen 443 ssl;
server_name ~^business\.(?<apex>.+)$;
ssl_certificate /etc/letsencrypt/live/meshkee-dashboards/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/meshkee-dashboards/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
location / {
root /var/www/meshkee/business;
try_files $uri $uri/ /index.html;
}
}
server {
listen 443 ssl;
server_name ~^customer\.(?<apex>.+)$;
ssl_certificate /etc/letsencrypt/live/meshkee-dashboards/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/meshkee-dashboards/privkey.pem;
ssl_protocols TLSv1.2 TLSv1.3;
location / {
root /var/www/meshkee/customer;
try_files $uri $uri/ /index.html;
}
}
server {
listen 80;
server_name manage.meshkee.com;
location /.well-known/acme-challenge/ { root /var/www/certbot; }
location / { return 301 https://$host$request_uri; }
}
server {
listen 80;
server_name ~^business\.(?<apex>.+)$;
location /.well-known/acme-challenge/ { root /var/www/certbot; }
location / { return 301 https://$host$request_uri; }
}
server {
listen 80;
server_name ~^customer\.(?<apex>.+)$;
location /.well-known/acme-challenge/ { root /var/www/certbot; }
location / { return 301 https://$host$request_uri; }
}