diff --git a/lith/Caddyfile b/lith/Caddyfile index f44ce47dda..0387cebf88 100644 --- a/lith/Caddyfile +++ b/lith/Caddyfile @@ -22,12 +22,17 @@ # staleness to ~1min.) @code path *.mjs *.js *.css *.lisp *.lua header @code Cache-Control "public, max-age=60, stale-while-revalidate=300" - header @code Access-Control-Allow-Origin * + # `?` = set only if absent. The upstream Express app (server.mjs) already + # sends Access-Control-Allow-Origin on proxied responses; adding a second + # copy here produced "*, *", which browsers reject (the same bug the IPFS + # block below hit). Set-if-absent yields exactly one header for both proxied + # and Caddy-served responses. + header @code ?Access-Control-Allow-Origin * # Static assets: long cache (1h fresh, serve stale for 24h while revalidating) @cacheable path *.woff2 *.woff *.ttf *.png *.jpg *.jpeg *.svg *.gif *.webp *.ico *.mp3 *.wav *.mp4 *.json header @cacheable Cache-Control "public, max-age=3600, stale-while-revalidate=86400" - header @cacheable Access-Control-Allow-Origin * + header @cacheable ?Access-Control-Allow-Origin * # set-if-absent — see @code note # Service workers must always revalidate — cached sw.js delays rollout of # bumped CACHE_NAME, pinning clients to stale module caches.