Add path-prefix deployment support for migrating to podsteadr's domain

Regress needs to live at podsteadr.atobitcoin.io/regress/ since / is
already podsteadr. Two coordinated pieces:
- VITE_BASE build arg (frontend asset/script paths, %BASE_URL% in
  index.html for the nostr-provider.js script tag)
- ROUTE_PREFIX runtime env (backend routes registered under the prefix
  via Fastify's plugin-encapsulation, including /api/health)

The nginx location must forward the prefix unstripped (proxy_pass with
no trailing path) — NIP-98 login signs the exact URL it calls, so a
stripped prefix makes the backend reconstruct a different URL than what
was signed and every login fails. Caught this with a real nginx+docker
integration test locally before it could break the live migration, then
fixed a matching bug in auth.ts (it was signing the unprefixed URL while
api.ts fetched the prefixed one). New routePrefix.test.ts proves the
prefix is actually enforced, including a negative case. 40 tests passing.

Also fixes a latent bug: import.meta.env usage had no vite/client type
reference, so it only ever passed typecheck by accident in earlier local
runs — added the standard vite-env.d.ts.
This commit is contained in:
2026-08-05 14:58:43 +00:00
parent df9a4ae74b
commit 517186ac55
11 changed files with 214 additions and 61 deletions
+18
View File
@@ -0,0 +1,18 @@
# Snippet added to podsteadr's existing /etc/nginx/sites-enabled/podsteadr,
# inside the existing `server { listen 443 ssl; ... }` block, alongside its
# /blossom/, /player/, /hls/, /whip/ locations.
#
# Unlike those locations, this one must NOT strip the /regress/ prefix —
# proxy_pass has no trailing path component, which tells nginx to forward
# the original request URI verbatim (prefix included). See README.md
# "Path-prefix deployment" for why: Regress's NIP-98 login signs the exact
# URL it calls, prefix included, and the backend (ROUTE_PREFIX=/regress)
# expects to see that same prefixed path.
location /regress/ {
proxy_pass http://127.0.0.1:8199;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}