All checks were successful
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Successful in 3m7s
Build and deploy / Secret scan and release gate (push) Successful in 10s
Build and deploy / Publish images (push) Successful in 1m6s
The order page becomes the customer's area, one page at four addresses: - /conta/entrar: sign in or create an account, side by side. "Esqueci minha senha" points to the Dropstar WhatsApp until e-mail can be sent. - /conta: the counts of orders waiting for payment, in production, in correction and finished, and the latest one. - /conta/pedidos: every order and the cart waiting for payment in one list, newest first, filtered by group, order number and period, ten per page. The cart shows "Aguardando pagamento" and its "Pagar" goes to the PIX page when a PIX code is open. An order opens in place with its progress, items, delivery, history, files and the correction form. A guest sees the orders paid in this browser. - /conta/dados: WhatsApp and a saved delivery address (the CNPJ is locked), e-mail and password changes, both confirmed with the current password; a password change signs the other devices out. The cart fills in the account's details and saved address. New API routes for the details, and the order list takes filters and pages and returns the counts; only the newest unpaid quote whose files still exist is listed. The Site's "Minha conta" and "Ver meus pedidos" point to the new addresses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
45 lines
2.3 KiB
Plaintext
45 lines
2.3 KiB
Plaintext
limit_req_zone $binary_remote_addr zone=api_limit:10m rate=20r/s;
|
|
server {
|
|
listen 80;
|
|
server_name localhost site kanban;
|
|
if ($host !~ ^(localhost|127\.0\.0\.1|site|kanban)$) { return 400; }
|
|
root /usr/share/nginx/html;
|
|
index ${WEB_INDEX};
|
|
add_header X-Content-Type-Options nosniff always;
|
|
add_header Referrer-Policy no-referrer always;
|
|
add_header X-Frame-Options DENY always;
|
|
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;
|
|
add_header Content-Security-Policy "default-src 'self'; script-src 'self' @SCRIPT_HASHES@ ${PAYMENT_CSP_SOURCES}; script-src-attr 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob: https://cdn.vnda.com.br ${PAYMENT_CSP_SOURCES}; connect-src 'self' ${S3_PUBLIC_ENDPOINT} https://cdn.vnda.com.br ${PAYMENT_CSP_SOURCES}; frame-src 'self' ${PAYMENT_CSP_SOURCES} ${PAYMENT_CHALLENGE_SOURCES}; worker-src 'self' blob:; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self' ${PAYMENT_CHALLENGE_SOURCES}" always;
|
|
location = /health { access_log off; return 200 'ok'; }
|
|
location /api/ {
|
|
limit_req zone=api_limit burst=100 nodelay;
|
|
limit_req_status 429;
|
|
proxy_pass http://api:8000;
|
|
proxy_set_header Host $http_host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
client_max_body_size 2m;
|
|
}
|
|
# The Site's product pages and cart are addresses of the same page (web/site-pages.js).
|
|
location ~ ^/(arquivo-por-metro|artes-avulsas|uv-arquivo-por-metro|uv-artes-avulsas|carrinho|pagamento|pagamento/pix)/?$ {
|
|
try_files /index.html =404;
|
|
}
|
|
# The customer's area: one page, which shows the right part for each address.
|
|
location ~ ^/conta(/(entrar|pedidos|dados))?/?$ {
|
|
try_files /portal.html =404;
|
|
}
|
|
location / { try_files $uri $uri/ =404; }
|
|
}
|
|
server {
|
|
listen 81;
|
|
server_name localhost site kanban;
|
|
if ($host !~ ^(localhost|127\.0\.0\.1|site|kanban)$) { return 400; }
|
|
client_max_body_size 2m;
|
|
location / {
|
|
limit_req zone=api_limit burst=100 nodelay;
|
|
limit_req_status 429;
|
|
proxy_pass http://api:8000;
|
|
proxy_set_header Host $http_host;
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
}
|
|
}
|