The nginx block is plain http; certbot adds the TLS server block and the redirect itself. It sets X-Forwarded-Proto, which is load-bearing: the app compares the browser's Origin against the URL it believes it is serving, and without that header it thinks it is on http while the browser says https, decides every save is cross-site and drops the session. Upstream's README is kept as README.nullboard.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UU1vyTHj3uE9PJYSxRxwkU