# Included inside the existing HTTPS server block. The process listens only on # loopback; Nginx terminates TLS so every client uses wss:// on port 443. location = /ws/music-bridge { proxy_pass http://127.0.0.1:47910; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_set_header Host $host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_read_timeout 75s; proxy_send_timeout 75s; } location ^~ /music-artwork/ { alias /srv/filyx/apps/web/storage/music-artwork/; autoindex off; add_header X-Content-Type-Options nosniff always; add_header Cache-Control "public, max-age=604800, immutable" always; }