Skip to content

[Bug]: F-28 Behind Caddy (and nginx without the documented rules) every page load downloads 11 MB of JavaScript and CSS #15702

Description

@nicolassp

⚠️ This issue respects the following points: ⚠️

  • This is not a troubleshooting question, general support matter, or webserver/proxy problem, but likely a bug (if unsure, ask the Community Help Forum).
  • This issue is not already reported on Github OR solved at the Community Help Forum (I've searched!).
  • I'm using a maintained major version of Nextcloud Server and tested against the latest patch level. (Supported major versions and current patch levels).
  • I agree to follow Nextcloud's Code of Conduct.
  • I've tried my best to provide clear reproduction steps that someone unfamiliar with this bug could use to reproduce it.

Bug description

F-28 · Behind Caddy (and nginx without the documented rules) every page load downloads 11 MB of JavaScript and CSS

Severity Performance (deployment; the slowest part of the web UI on remote connections)
Component web server configuration, .htaccess equivalents
Affects installations not served by Apache, e.g. nextcloud:fpm with Caddy
Verified Measured with a browser against Caddy with and without the rules

Measurement (Files app, 50 Mbit/s, 20 ms latency)

without with compression and caching
Transferred on the first visit 11.0 MB 2.7 MB
Time until the file list shows 3.7 s 2.2 s
core-common.js 5.7 MB 1.2 MB (zstd)

Without Cache-Control, browsers revalidate or download the 65 scripts and 45 stylesheets again.
Apache gets these rules from .htaccess (max-age=15778463, immutable for versioned assets);
Caddy and nginx need them in their own configuration. With encode zstd gzip the bundles shrink to
a quarter.

The rules must only match files that exist on disk (Caddy file matcher), as FilesMatch does in
Apache. A plain path *.css matcher also hits PHP routes such as /apps/theming/theme/default.css
and /apps/theming/img/core/filetypes/*.svg. Caddy then sends a second Cache-Control header
next to the one from PHP (private, max-age=86400, must-revalidate), and browsers cache the theme
CSS for half a year. The snippet in docs/nextcloud-perf.caddy uses the file matcher and was
checked against both kinds of URL.

Steps to reproduce

see the top

Expected behavior

see the top

Nextcloud Server version

35

Operating system

No response

PHP engine version

No response

Web server

No response

Database engine version

No response

Is this bug present after an update or on a fresh install?

No response

Are you using the Nextcloud Server Encryption module?

No response

What user-backends are you using?

  • Default user-backend (database)
  • LDAP/ Active Directory
  • SSO - SAML
  • Other

Configuration report

List of activated Apps

Nextcloud Signing status

Nextcloud Logs

Additional info

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions