常用基本配置
- 隐藏版本号
1 | http { |
curl -I 你的网站看看就没有了版本号了
- 设置上传大小
1 | server { |
代理后端下载大文件504 网关超时 504 gateway timeout
1
2
3
4
5location /xx {
proxy_connect_timeout 600s;
proxy_send_timeout 600s;
proxy_read_timeout 600s;
}代理websock
1
2
3
4
5
6location /websocket {
proxy_pass http://backend;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
}获取真实ip
1
2
3
4
5
6location /websocket {
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}漏扫出现问题
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18location /mp/ {
proxy_pass http://192.168.60.162:8060/;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header REMOTE-HOST $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
# 漏扫出现问题
add_header X-Content-Type-Options nosniff;
add_header 'Referrer-Policy' 'origin';
add_header X-Download-Options "noopen" always;
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains; preload";
add_header X-Permitted-Cross-Domain-Policies "master-only";
add_header X-Frame-Options SAMEORIGIN;
#add_header Content-Security-Policy "default-src 'self' at.alicdn.com cdnjs.cloudflare.com 'unsafe-inline' 'unsafe-eval' blob: data: ;"
add_header Content-Security-Policy "default-src 'self' *.alicdn.com *.cloudflare.com 'unsafe-inline' 'unsafe-eval' blob: data: ;";
add_header X-Content-Type-Options: nosniff;
add_header X-XSS-Protection "1; mode=block";
1 | location /xxx/ { |
本博客所有文章除特别声明外,均采用 CC BY-NC-SA 4.0 许可协议。转载请注明来自 树灼的博客!


