Repository navigation
docs(npm): add optional advanced config section for performance and security - #579
Merged
Merged
Conversation
…ecurity 在 Nginx Proxy Manager 反代文档末尾追加「进阶配置:性能与安全(可选)」小节, 补全 NPM 默认未覆盖的优化与响应头,所有配置均为反代层通用、与具体主题无关。 内容包括: - gzip 配置补齐 JS、字体、JSON 等 MIME 类型(解决 NPM 默认只压 HTML/CSS 问题) - proxy_buffers 调大避免较大响应落盘 - 5 个主流安全响应头(X-Content-Type-Options / X-Frame-Options / X-XSS-Protection / Referrer-Policy / Permissions-Policy),带 always 确保错误页也返回 - HSTS 单独说明:先短 max-age 验证再逐步调大,preload 提交需谨慎 - RSS 路径别名:/rss 与 /feed 301 跳转到 /rss.xml - 验证命令(curl + DevTools) - FAQ:A+/CSP 路径、NPM 缓存开关建议、proxy buffer 的作用 现有基础教程内容未改动。
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ruibaby The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
当前 Nginx Proxy Manager 反向代理 文档很好地覆盖了基础场景(添加代理记录、申请 SSL),但对一些用户在生产环境会遇到的两个常见问题没有展开:
gzip_types只压 HTML/CSS,JavaScript、字体、JSON 等静态资源未启用 gzip。例如一个 ~90 KB 的主题 JS 文件,gzip 后大约 25–30 KB,差距明显。本 PR 将这些通用优化以可选小节的形式补入现有文档,帮助用户通过 NPM 的 Advanced → Custom Nginx Configuration 一次性启用。
本 PR 做了什么
在现有文档末尾追加
## 进阶配置:性能与安全(可选)一节,不改动任何现有内容(diff 是纯追加 +116 行)。内容包括:gzip_types补齐 JS / 字体 / JSON / SVG / atom+rss 等 MIME 类型,加gzip_static onproxy_buffers 16 32k+proxy_buffer_size 64k避免较大响应临时落盘设计原则
实践验证
配置在生产环境 Halo 博客上验证过:
兼容性
欢迎 review,如有任何调整建议随时指出。