# TLS edge (rendered automatically once certs exist for ${DOMAIN}).
# Commerce portal: ${DOMAIN}
# Finance portal:  ${FINANCE_DOMAIN}

server {
    listen 80;
    listen [::]:80;
    server_name ${DOMAIN} ${FINANCE_DOMAIN};

    location ^~ /.well-known/acme-challenge/ {
        root /var/www/certbot;
        default_type "text/plain";
    }

    location / {
        return 301 https://$host$request_uri;
    }
}

server {
    listen 443 ssl;
    listen [::]:443 ssl;
    http2 on;
    server_name ${DOMAIN};
    client_max_body_size 72M;

    ssl_certificate     /etc/letsencrypt/live/${DOMAIN}/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/${DOMAIN}/privkey.pem;
    ssl_protocols       TLSv1.2 TLSv1.3;
    ssl_session_cache   shared:SSL:10m;
    ssl_session_timeout 1d;

    add_header Strict-Transport-Security "max-age=31536000" always;

    include /etc/nginx/snippets/app-locations.conf;
}

#__FINANCE_TLS_BEGIN__
server {
    listen 443 ssl;
    listen [::]:443 ssl;
    http2 on;
    server_name ${FINANCE_DOMAIN};
    client_max_body_size 72M;

    # Prefer a dedicated cert; fall back to the commerce cert if it is a SAN
    # that already includes FINANCE_DOMAIN (same live/ dir name as DOMAIN).
    ssl_certificate     /etc/letsencrypt/live/${FINANCE_SSL_NAME}/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/${FINANCE_SSL_NAME}/privkey.pem;
    ssl_protocols       TLSv1.2 TLSv1.3;
    ssl_session_cache   shared:SSL:10m;
    ssl_session_timeout 1d;

    add_header Strict-Transport-Security "max-age=31536000" always;

    include /etc/nginx/snippets/finance-locations.conf;
}
#__FINANCE_TLS_END__
