Enable nginx X-Accel for original artwork downloads.

Hand originals to nginx after auth so PHP is not in the byte path. Keep DOWNLOAD_ACCEL_ENABLED off until the internal location is verified.
This commit is contained in:
2026-08-29 12:25:37 +02:00
parent fb560fb7dd
commit e9cf754b37
7 changed files with 411 additions and 35 deletions
+12 -30
View File
@@ -1,36 +1,18 @@
# -----------------------------------------------------------------------
# nginx X-Accel-Redirect for artwork original file downloads
# M13 — nginx X-Accel-Redirect for GET /download/artwork/{id}
#
# Problem: PHP streams the file body through FPM → nginx, causing
# "[warn] upstream response is buffered to a temporary file"
# for large downloads because FastCGI buffers are too small.
# Production vhost is NOT in this repository (live file:
# /etc/nginx/sites-enabled/skinbase.org.conf).
# Insert this location inside the HTTPS server { } block, before the
# catch-all `location /` and any regex locations that could steal the URI.
#
# Solution: PHP sets X-Accel-Redirect, nginx serves the file body
# directly from disk — FPM is only used for the header response.
# Trailing slashes are required: location prefix and alias both end with /.
# Use the canonical shared storage tree so release switches do not break nginx.
# Do not use `root` here.
#
# Setup:
# 1. Set DOWNLOAD_ACCEL_PATH=/internal/originals in .env (production).
# 2. Include this file inside your server {} block:
# include /etc/nginx/conf.d/download-accel.conf;
# 3. Make sure the nginx worker has read access to the originals path.
#
# The /internal/originals prefix MUST match DOWNLOAD_ACCEL_PATH in .env.
# The alias path MUST match ARTWORKS_LOCAL_ORIGINALS_ROOT on the server.
# -----------------------------------------------------------------------
# Direct GET /internal/originals/... must 404 (internal;).
# Laravel still authorizes/counts; only the file body is offloaded.
location /internal/originals/ {
# Block direct client access — only X-Accel-Redirect headers trigger this.
location ^~ /internal/originals/ {
internal;
# Replace this with the actual absolute path to artwork originals on disk.
# Typically: /var/www/skinbase/storage/originals or /var/www/skinbase/public/files/originals
alias /var/www/skinbase/public/files/originals/;
# Let nginx send the file efficiently with sendfile + tcp_nopush.
sendfile on;
tcp_nopush on;
tcp_nodelay on;
# No nginx-level caching for download responses (private files).
add_header Cache-Control "private, no-store";
alias /opt/www/virtual/SkinbaseNova.releases/shared/storage/app/originals/artworks/;
}