diff options
| author | Ken D'Ambrosio <ken@jots.org> | 2026-06-16 18:43:26 +0000 |
|---|---|---|
| committer | Ken D'Ambrosio <ken@jots.org> | 2026-06-16 18:43:26 +0000 |
| commit | a0803c8e87f375b1f138c7d1650ba21108f1cc62 (patch) | |
| tree | b523e79df910999effae48a5fb1af9736308e62a /config/nginx-albumen.conf | |
| parent | be80a08c6a2a330e81d43fbfd345f05199e75947 (diff) | |
Fix WhatsApp/OG link previews: https URLs and correct image dimensions
nginx was sending X-Forwarded-Proto: http (its own scheme) rather than
https (the edge scheme), so og:url and og:image were http:// URLs.
Fixed by hardcoding https in the nginx proxy_set_header since HTTPS is
always terminated at the upstream Apache router.
Added a 1200x630 landscape og-default.png (WhatsApp requires ~1.91:1
ratio) and explicit og:image:width/height meta tags. Also tracks the
nginx site config in the repo.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Diffstat (limited to 'config/nginx-albumen.conf')
| -rw-r--r-- | config/nginx-albumen.conf | 6 |
1 files changed, 5 insertions, 1 deletions
diff --git a/config/nginx-albumen.conf b/config/nginx-albumen.conf index d540bcd..ce143f3 100644 --- a/config/nginx-albumen.conf +++ b/config/nginx-albumen.conf @@ -2,6 +2,10 @@ server { listen 80; server_name albumen.jots.org; + # Apache reverse proxy on the router passes X-Forwarded-For with the real client IP. + real_ip_header X-Forwarded-For; + set_real_ip_from 192.168.10.1; + client_max_body_size 0; # no limit for large video uploads via rsync proxy_read_timeout 300s; proxy_send_timeout 300s; @@ -12,7 +16,7 @@ server { proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; - proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header X-Forwarded-Proto https; proxy_buffering off; } } |
