All checks were successful
Build and deploy / Validate source (push) Successful in 5s
Build and deploy / Integration suite on a real stack (push) Successful in 2m3s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images (push) Successful in 1m31s
The payment page lists credit card (preselected), debit card and PIX. Each card option limits Mercado Pago's form to its kind; debit is paid at once. Card payments ask for 3-D Secure when the issuer requires it, and a challenge opens the bank's page in a frame, which needs PAYMENT_CHALLENGE_SOURCES=https: (frames and form posts only). A card left waiting for that confirmation stops blocking a new attempt after ten minutes, and a refusal reported by the notification returns the customer to the payment choice. Written from the documentation; not yet run with a real debit card. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
61 lines
3.2 KiB
Plaintext
61 lines
3.2 KiB
Plaintext
limit_req_zone $binary_remote_addr zone=api_limit:10m rate=20r/s;
|
|
server {
|
|
listen 8080;
|
|
server_name ${PUBLIC_HOST};
|
|
if ($host != ${PUBLIC_HOST}) { return 400; }
|
|
# Resolve through Docker's embedded DNS at request time. This prevents
|
|
# Nginx from exiting during a Swarm rollout when the API task is briefly
|
|
# unavailable or still creating its database schema.
|
|
resolver 127.0.0.11 ipv6=off valid=10s;
|
|
set $api_upstream api:8000;
|
|
|
|
# This gateway sits behind the host's reverse proxy, so $remote_addr is that
|
|
# proxy, not the customer. Recover the real address from the header it sets,
|
|
# and only when the connection comes from a private network: a request that
|
|
# reaches the published port directly from the internet is not trusted, so
|
|
# its X-Forwarded-For is ignored and $remote_addr stays the actual peer.
|
|
set_real_ip_from 10.0.0.0/8;
|
|
set_real_ip_from 172.16.0.0/12;
|
|
set_real_ip_from 192.168.0.0/16;
|
|
real_ip_header X-Forwarded-For;
|
|
real_ip_recursive on;
|
|
root /usr/share/nginx/html;
|
|
index ${WEB_INDEX};
|
|
|
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
|
add_header X-Content-Type-Options nosniff always;
|
|
add_header Referrer-Policy no-referrer always;
|
|
add_header X-Frame-Options DENY always;
|
|
add_header Permissions-Policy "camera=(), microphone=(), geolocation=()" always;
|
|
add_header Content-Security-Policy "default-src 'self'; script-src 'self' @SCRIPT_HASHES@ ${PAYMENT_CSP_SOURCES}; script-src-attr 'none'; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: blob: https://cdn.vnda.com.br ${PAYMENT_CSP_SOURCES}; connect-src 'self' ${S3_PUBLIC_ENDPOINT} https://cdn.vnda.com.br ${PAYMENT_CSP_SOURCES}; frame-src 'self' ${PAYMENT_CSP_SOURCES} ${PAYMENT_CHALLENGE_SOURCES}; worker-src 'self' blob:; object-src 'none'; base-uri 'none'; frame-ancestors 'none'; form-action 'self' ${PAYMENT_CHALLENGE_SOURCES}" always;
|
|
|
|
location = /health { access_log off; return 200 'ok'; }
|
|
location /api/ {
|
|
limit_req zone=api_limit burst=100 nodelay;
|
|
limit_req_status 429;
|
|
proxy_pass http://$api_upstream;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Forwarded-Host $host;
|
|
proxy_set_header X-Forwarded-Proto https;
|
|
# Overwrite, never append: $proxy_add_x_forwarded_for keeps any header the
|
|
# client sent, and the leftmost value would then be attacker-controlled.
|
|
# After real_ip above, $remote_addr is the customer even behind the proxy.
|
|
proxy_set_header X-Forwarded-For $remote_addr;
|
|
proxy_connect_timeout 5s;
|
|
proxy_read_timeout 30s;
|
|
client_max_body_size 2m;
|
|
}
|
|
# Always revalidate HTML/JS/CSS after a deployment. Without this, a browser
|
|
# can pair a new Kanban page with a cached older script after a rollout.
|
|
# The Site's product pages and cart are addresses of the same page (web/site-pages.js).
|
|
location ~ ^/(arquivo-por-metro|artes-avulsas|uv-arquivo-por-metro|uv-artes-avulsas|carrinho|pagamento|pagamento/pix)/?$ {
|
|
expires -1;
|
|
try_files /index.html =404;
|
|
}
|
|
location / {
|
|
expires -1;
|
|
try_files $uri $uri/ =404;
|
|
}
|
|
}
|