diff --git a/nginx.conf b/nginx.conf index 707e0930..c287588a 100644 --- a/nginx.conf +++ b/nginx.conf @@ -78,6 +78,29 @@ server { try_files $uri =404; } + # atproto identity documents. Browser-based resolvers fetch these + # cross-origin (handle -> DID via atproto-did, then DID -> doc via + # did.json), so CORS must be open. GET-only public documents; plain GETs + # are "simple" CORS requests, so no preflight handling is needed. + # `add_header` here cancels the server-level headers (see note at top); + # nosniff is repeated, CSP is irrelevant for non-HTML documents. + location = /.well-known/did.json { + add_header Access-Control-Allow-Origin "*" always; + add_header X-Content-Type-Options "nosniff" always; + add_header Cache-Control "no-cache"; + try_files $uri =404; + } + + location = /.well-known/atproto-did { + # no file extension, so nginx would default to application/octet-stream; + # the spec wants text/plain + default_type text/plain; + add_header Access-Control-Allow-Origin "*" always; + add_header X-Content-Type-Options "nosniff" always; + add_header Cache-Control "no-cache"; + try_files $uri =404; + } + location = /index.html { add_header Cache-Control "no-cache"; # repeated because the `add_header` above cancels inheritance of the diff --git a/public/.well-known/atproto-did b/public/.well-known/atproto-did new file mode 100644 index 00000000..549cc9e0 --- /dev/null +++ b/public/.well-known/atproto-did @@ -0,0 +1 @@ +did:web:lexidraw.app diff --git a/public/.well-known/did.json b/public/.well-known/did.json new file mode 100644 index 00000000..9eff2c08 --- /dev/null +++ b/public/.well-known/did.json @@ -0,0 +1,26 @@ +{ + "@context": [ + "https://www.w3.org/ns/did/v1", + "https://w3id.org/security/multikey/v1", + "https://w3id.org/security/suites/secp256k1-2019/v1" + ], + "id": "did:web:lexidraw.app", + "alsoKnownAs": [ + "at://lexidraw.app" + ], + "verificationMethod": [ + { + "id": "did:web:lexidraw.app#atproto", + "type": "Multikey", + "controller": "did:web:lexidraw.app", + "publicKeyMultibase": "zQ3shp3W2RFYycXFrrJoNAa2PeRnVabnqGd9RFVUQg1pn4a1j" + } + ], + "service": [ + { + "id": "#atproto_pds", + "type": "AtprotoPersonalDataServer", + "serviceEndpoint": "https://selfhosted.social" + } + ] +}