From 9b3a69d296028f82cb1f0e7ae66b433b5045374a Mon Sep 17 00:00:00 2001 From: Pavel Fedin Date: Thu, 24 Sep 2026 12:41:40 +0300 Subject: [PATCH] * server protected files queries in PHP application --- config/nginx/includes.d/octobercms.conf | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/config/nginx/includes.d/octobercms.conf b/config/nginx/includes.d/octobercms.conf index fbb713f..18e9903 100644 --- a/config/nginx/includes.d/octobercms.conf +++ b/config/nginx/includes.d/octobercms.conf @@ -22,6 +22,13 @@ location ~ ^/.*\.xml { try_files $uri /index.php; } location = /robots.txt { try_files $uri /index.php; } location = /humans.txt { try_files $uri /index.php; } +## Protected uploads are served only by the application (signed urls), never as static files +## ^~ stops regex locations (jpg, png, pdf...) from serving them directly + +location ^~ /storage/app/uploads/protected/ { + rewrite ^ /index.php last; +} + ## Let nginx return 404 if static file not exists location /storage/app/uploads/public {