# Caddy reverse proxy for Eversolo Web
# Domain: test.luxsin.com.cn
# Caddy automatically obtains and renews SSL certificates via Let's Encrypt / ZeroSSL.
# HTTP (port 80) is automatically redirected to HTTPS.

test.luxsin.com.cn {
	# Security headers (applied to all responses)
	header {
		X-Content-Type-Options nosniff
		X-Frame-Options SAMEORIGIN
		Referrer-Policy strict-origin-when-cross-origin
	}

	# Payload uploads served directly from the persistent data volume.
	# docker-compose mounts ./data/{media,files,videos} -> /srv/uploads/{media,files,videos}
	# handle creates an exclusive route: once matched, the request never falls through to the app.
	handle /media/* {
		root * /srv/uploads
		header Cache-Control "public, max-age=2592000, immutable"
		file_server
	}

	handle /files/* {
		root * /srv/uploads
		header Cache-Control "public, max-age=604800"
		file_server
	}

	handle /videos/* {
		root * /srv/uploads
		header Cache-Control "public, max-age=2592000"
		file_server
	}

	# Everything else -> Next.js app (port 3000)
	# WebSocket upgrade headers are handled automatically by Caddy.
	handle {
		reverse_proxy app:3000 {
			header_up X-Real-IP {remote_host}
			transport http {
				read_timeout 300s
				write_timeout 300s
			}
		}
	}
}
