# /etc/nginx/sites-available/labelinfo  (certificat : sudo certbot --nginx -d labelinfo.tv -d www.labelinfo.tv)
server {
    listen 80;
    server_name labelinfo.tv www.labelinfo.tv;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl http2;
    server_name labelinfo.tv www.labelinfo.tv;
    # ssl_certificate / ssl_certificate_key : ajoutés par certbot

    client_max_body_size 25M;   # médias : 10 Mo image / 20 Mo document

    location /static/ {
        alias /var/www/labelinfo/staticfiles/;
        expires 30d;
        add_header Cache-Control "public";
    }

    # Fichiers téléversés (même préfixe que Laravel : les anciennes URL restent valides)
    location /storage/ {
        alias /var/www/labelinfo/storage/;
        expires 7d;
        add_header X-Content-Type-Options nosniff;
        location ~* \.(php|py|pl|sh|cgi|html?)$ { deny all; }
    }

    location / {
        proxy_pass http://unix:/run/labelinfo/gunicorn.sock;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_read_timeout 60s;
    }
}
