diff --git a/docker/nginx/prod.conf b/docker/nginx/prod.conf index dea05a2..9651651 100644 --- a/docker/nginx/prod.conf +++ b/docker/nginx/prod.conf @@ -25,6 +25,17 @@ server { if ($request_method = POST) { set $skip_cache 1; } if ($request_uri ~* "^/(boboko|up)") { set $skip_cache 1; } if ($query_string) { set $skip_cache 1; } + # Any logged-in request must never be served a cached response — + # the cache key is URL-only ($scheme$request_method$host$request_uri, + # see fastcgi_cache_key below), with no per-session variation. Without + # this, the first cached hit on an authenticated GET page (e.g. + # /account) gets replayed verbatim to every other visitor of that same + # URL for up to fastcgi_cache_valid's 10m window — a real account/ + # session data leak, not just a staleness bug. Laravel's session + # cookie name is env('SESSION_COOKIE', Str::slug(APP_NAME).'-session') + # (config/session.php) — APP_NAME varies per environment, so this + # matches the fixed '-session' suffix rather than a hardcoded name. + if ($http_cookie ~* "-session") { set $skip_cache 1; } # Vite build assets — content-hashed filenames, safe to cache forever location /build/ {