summaryrefslogtreecommitdiffstats
path: root/config/nginx-albumen.conf
diff options
context:
space:
mode:
authorKen D'Ambrosio <ken@jots.org>2026-06-16 18:43:26 +0000
committerKen D'Ambrosio <ken@jots.org>2026-06-16 18:43:26 +0000
commita0803c8e87f375b1f138c7d1650ba21108f1cc62 (patch)
treeb523e79df910999effae48a5fb1af9736308e62a /config/nginx-albumen.conf
parentbe80a08c6a2a330e81d43fbfd345f05199e75947 (diff)
Fix WhatsApp/OG link previews: https URLs and correct image dimensions
nginx was sending X-Forwarded-Proto: http (its own scheme) rather than https (the edge scheme), so og:url and og:image were http:// URLs. Fixed by hardcoding https in the nginx proxy_set_header since HTTPS is always terminated at the upstream Apache router. Added a 1200x630 landscape og-default.png (WhatsApp requires ~1.91:1 ratio) and explicit og:image:width/height meta tags. Also tracks the nginx site config in the repo. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Diffstat (limited to 'config/nginx-albumen.conf')
-rw-r--r--config/nginx-albumen.conf6
1 files changed, 5 insertions, 1 deletions
diff --git a/config/nginx-albumen.conf b/config/nginx-albumen.conf
index d540bcd..ce143f3 100644
--- a/config/nginx-albumen.conf
+++ b/config/nginx-albumen.conf
@@ -2,6 +2,10 @@ server {
listen 80;
server_name albumen.jots.org;
+ # Apache reverse proxy on the router passes X-Forwarded-For with the real client IP.
+ real_ip_header X-Forwarded-For;
+ set_real_ip_from 192.168.10.1;
+
client_max_body_size 0; # no limit for large video uploads via rsync
proxy_read_timeout 300s;
proxy_send_timeout 300s;
@@ -12,7 +16,7 @@ server {
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
- proxy_set_header X-Forwarded-Proto $scheme;
+ proxy_set_header X-Forwarded-Proto https;
proxy_buffering off;
}
}