Build and Deploy Verso / deploy (push) Successful in 11m0s
clsi-nginx.conf: the types{} block was overriding all nginx defaults,
leaving HTML/CSS/JS/fonts as application/octet-stream. Add the full
set of web MIME types so RevealJS assets are served correctly. Also
needed for X-Content-Type-Options: nosniff to pass.
CompileController.js: success was hardcoded to require output.pdf.
Also accept output.html so a RevealJS compile is reported as
'success' rather than 'failure'.
QuartoRunner.js: remove hardcoded --to typst --output output.pdf.
Instead run `quarto render` without --to/--output so the YAML
frontmatter decides the format (typst → PDF, revealjs → HTML, etc.).
Pass --embed-resources so HTML output is self-contained (flag is
silently ignored by the typst backend). After render, rename
main.pdf → output.pdf or main.html → output.html so the pipeline
finds the standard canonical filename.
output-files.ts: handleOutputFiles now falls back to output.html when
output.pdf is absent. Download URL uses outputFile.path instead of
the hardcoded 'output.pdf' string.
pdf-viewer.tsx: when pdfUrl contains output.html, bypass PDF.js
entirely and render a sandboxed iframe (allow-scripts for RevealJS
interactivity, allow-presentation for fullscreen).
Usage: set `format: revealjs` in the .qmd YAML frontmatter to get
an HTML presentation preview; set `format: typst` for PDF.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
71 lines
2.4 KiB
Plaintext
71 lines
2.4 KiB
Plaintext
# keep in sync with services/clsi/nginx.conf
|
|
# Changes to the above:
|
|
# - added Security-Headers
|
|
# - remove CORS rules, Server-CE/Server-Pro runs behind a single origin
|
|
# - change /output path to /var/lib/overleaf/data/output
|
|
# - remove tiny.pdf endpoints
|
|
|
|
server {
|
|
add_header 'X-Served-By' 'clsi-nginx' always;
|
|
|
|
# Security-Headers
|
|
add_header 'X-Content-Type-Options' 'nosniff' always;
|
|
add_header 'X-Download-Options' 'noopen' always;
|
|
add_header 'X-Frame-Options' 'SAMEORIGIN' always;
|
|
add_header 'X-XSS-Protection' '1; mode=block' always;
|
|
|
|
listen 8080;
|
|
server_name clsi-nginx;
|
|
server_tokens off;
|
|
access_log off;
|
|
# Ignore symlinks possibly created by users
|
|
disable_symlinks on;
|
|
# enable compression for tex auxiliary files, but not for pdf files
|
|
gzip on;
|
|
gzip_types text/plain;
|
|
gzip_proxied any;
|
|
types {
|
|
text/html html htm;
|
|
text/css css;
|
|
application/javascript js;
|
|
application/json json;
|
|
image/svg+xml svg svgz;
|
|
image/png png;
|
|
image/jpeg jpeg jpg;
|
|
image/gif gif;
|
|
image/webp webp;
|
|
font/woff woff;
|
|
font/woff2 woff2;
|
|
application/pdf pdf;
|
|
text/plain log blg aux stdout stderr txt;
|
|
}
|
|
# handle output files for specific users
|
|
location ~ ^/project/([0-9a-f]+)/user/([0-9a-f]+)/build/([0-9a-f-]+)/output/(.+)$ {
|
|
rewrite ^/project/([0-9a-f]+)/user/([0-9a-f]+)/build/([0-9a-f-]+)/output/(.+)$ /$4 break;
|
|
root /var/lib/overleaf/data/output/$1-$2/generated-files/$3/;
|
|
}
|
|
# handle output files for anonymous users
|
|
location ~ ^/project/([0-9a-f]+)/build/([0-9a-f-]+)/output/(.+)$ {
|
|
rewrite ^/project/([0-9a-f]+)/build/([0-9a-f-]+)/output/(.+)$ /$3 break;
|
|
root /var/lib/overleaf/data/output/$1/generated-files/$2/;
|
|
}
|
|
|
|
# PDF range for specific users
|
|
location ~ ^/project/([0-9a-f]+)/user/([0-9a-f]+)/content/([0-9a-f-]+/[0-9a-f]+)$ {
|
|
# Cache for one day
|
|
expires 1d;
|
|
alias /var/lib/overleaf/data/output/$1-$2/content/$3;
|
|
}
|
|
# PDF range for anonymous users
|
|
location ~ ^/project/([0-9a-f]+)/content/([0-9a-f-]+/[0-9a-f]+)$ {
|
|
# Cache for one day
|
|
expires 1d;
|
|
alias /var/lib/overleaf/data/output/$1/content/$2;
|
|
}
|
|
|
|
# Do not look up any non matching files in the default root.
|
|
location / {
|
|
return 404;
|
|
}
|
|
}
|