diff --git a/deployment/proxy/nginx-cms.conf b/deployment/proxy/nginx-cms.conf index a9ed287a..1b5f6f2a 100644 --- a/deployment/proxy/nginx-cms.conf +++ b/deployment/proxy/nginx-cms.conf @@ -194,8 +194,8 @@ server { # Abuse limits. Deliberately NOT set at server scope: a room load and a page # load are not the same request profile, so each location picks its own zone. - # Locations without an explicit limit_req inherit nothing and are unlimited — - # the page/API routes below carry the budget instead. + # /gamedata/* has no request limit at all — it is a disk cache, so limiting + # it only cost players their icons. The page routes carry the budget. limit_conn cms_conn_per_ip 30; # Traefik health-check route herstellen @@ -266,7 +266,10 @@ server { add_header Cache-Control "public, max-age=300, must-revalidate"; access_log off; add_header Cache-Tag "cms-gamedata"; - limit_req zone=cms_static_per_ip burst=1000 nodelay; + + # Geen limit_req: gamedata is schijf-cache, geen CMS-backend. Een + # kamerladen vuurt honderden bestanden in één burst af en elke limiet + # hier leidde alleen tot zichtbaar gemiste icons. add_header Access-Control-Allow-Origin $http_origin always; add_header Access-Control-Allow-Methods "GET, OPTIONS" always; @@ -282,7 +285,10 @@ server { add_header Cache-Control "public, max-age=3600, must-revalidate"; access_log off; add_header Cache-Tag "cms-gamedata"; - limit_req zone=cms_static_per_ip burst=1000 nodelay; + + # Geen limit_req: gamedata is schijf-cache, geen CMS-backend. Een + # kamerladen vuurt honderden bestanden in één burst af en elke limiet + # hier leidde alleen tot zichtbaar gemiste icons. add_header Access-Control-Allow-Origin $http_origin always; add_header Access-Control-Allow-Methods "GET, OPTIONS" always;