server { listen %%interface%%:%%port%% default_server; include /etc/nginx/includes/server_params.conf; client_max_body_size 0; location / { proxy_pass http://127.0.0.1:8080; # SABnzbd refuses any request whose Host is not an IP literal # ("Access denied - Hostname verification failed"), so send the # upstream socket rather than the browser's host. X-Forwarded-For is # the only other header it reads (for its verify_xff_header option). proxy_set_header Host $proxy_host; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # The interface itself only emits relative links, so no body # rewriting is needed. Redirects are the exception: Raiser() emits # a path under url_base, so prefix them with the ingress entry. # absolute_redirect must stay off, or nginx expands the rewritten # Location into http://:/..., a port the # browser cannot reach. proxy_redirect / %%ingress_entry%%/; absolute_redirect off; # The login cookie is hardcoded to Path=/, which on the ingress # origin would send it to every other add-on's ingress path too. proxy_cookie_path / %%ingress_entry%%/; proxy_http_version 1.1; proxy_read_timeout 86400s; proxy_send_timeout 86400s; } }