Enable nginx X-Accel for original artwork downloads.
Hand originals to nginx after auth so PHP is not in the byte path. Keep DOWNLOAD_ACCEL_ENABLED off until the internal location is verified.
This commit is contained in:
@@ -1,36 +1,18 @@
|
||||
# -----------------------------------------------------------------------
|
||||
# nginx X-Accel-Redirect for artwork original file downloads
|
||||
# M13 — nginx X-Accel-Redirect for GET /download/artwork/{id}
|
||||
#
|
||||
# Problem: PHP streams the file body through FPM → nginx, causing
|
||||
# "[warn] upstream response is buffered to a temporary file"
|
||||
# for large downloads because FastCGI buffers are too small.
|
||||
# Production vhost is NOT in this repository (live file:
|
||||
# /etc/nginx/sites-enabled/skinbase.org.conf).
|
||||
# Insert this location inside the HTTPS server { } block, before the
|
||||
# catch-all `location /` and any regex locations that could steal the URI.
|
||||
#
|
||||
# Solution: PHP sets X-Accel-Redirect, nginx serves the file body
|
||||
# directly from disk — FPM is only used for the header response.
|
||||
# Trailing slashes are required: location prefix and alias both end with /.
|
||||
# Use the canonical shared storage tree so release switches do not break nginx.
|
||||
# Do not use `root` here.
|
||||
#
|
||||
# Setup:
|
||||
# 1. Set DOWNLOAD_ACCEL_PATH=/internal/originals in .env (production).
|
||||
# 2. Include this file inside your server {} block:
|
||||
# include /etc/nginx/conf.d/download-accel.conf;
|
||||
# 3. Make sure the nginx worker has read access to the originals path.
|
||||
#
|
||||
# The /internal/originals prefix MUST match DOWNLOAD_ACCEL_PATH in .env.
|
||||
# The alias path MUST match ARTWORKS_LOCAL_ORIGINALS_ROOT on the server.
|
||||
# -----------------------------------------------------------------------
|
||||
# Direct GET /internal/originals/... must 404 (internal;).
|
||||
# Laravel still authorizes/counts; only the file body is offloaded.
|
||||
|
||||
location /internal/originals/ {
|
||||
# Block direct client access — only X-Accel-Redirect headers trigger this.
|
||||
location ^~ /internal/originals/ {
|
||||
internal;
|
||||
|
||||
# Replace this with the actual absolute path to artwork originals on disk.
|
||||
# Typically: /var/www/skinbase/storage/originals or /var/www/skinbase/public/files/originals
|
||||
alias /var/www/skinbase/public/files/originals/;
|
||||
|
||||
# Let nginx send the file efficiently with sendfile + tcp_nopush.
|
||||
sendfile on;
|
||||
tcp_nopush on;
|
||||
tcp_nodelay on;
|
||||
|
||||
# No nginx-level caching for download responses (private files).
|
||||
add_header Cache-Control "private, no-store";
|
||||
alias /opt/www/virtual/SkinbaseNova.releases/shared/storage/app/originals/artworks/;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user