# HTTP-only edge (used until a TLS certificate is present for ${DOMAIN}).
# Commerce portal: ${DOMAIN}
# Finance portal:  ${FINANCE_DOMAIN}  (omit DNS / leave unset to skip — see entrypoint)

server {
    listen 80;
    listen [::]:80;
    server_name ${DOMAIN};
    client_max_body_size 72M;

    # ACME HTTP-01 challenge (certbot webroot).
    location ^~ /.well-known/acme-challenge/ {
        root /var/www/certbot;
        default_type "text/plain";
    }

    include /etc/nginx/snippets/app-locations.conf;
}

# Finance SPA — only rendered when FINANCE_DOMAIN is non-empty (entrypoint).
#__FINANCE_HTTP_BEGIN__
server {
    listen 80;
    listen [::]:80;
    server_name ${FINANCE_DOMAIN};
    client_max_body_size 72M;

    location ^~ /.well-known/acme-challenge/ {
        root /var/www/certbot;
        default_type "text/plain";
    }

    include /etc/nginx/snippets/finance-locations.conf;
}
#__FINANCE_HTTP_END__
