Hand originals to nginx after auth so PHP is not in the byte path. Keep DOWNLOAD_ACCEL_ENABLED off until the internal location is verified.
19 lines
770 B
Plaintext
19 lines
770 B
Plaintext
# M13 — nginx X-Accel-Redirect for GET /download/artwork/{id}
|
|
#
|
|
# Production vhost is NOT in this repository (live file:
|
|
# /etc/nginx/sites-enabled/skinbase.org.conf).
|
|
# Insert this location inside the HTTPS server { } block, before the
|
|
# catch-all `location /` and any regex locations that could steal the URI.
|
|
#
|
|
# Trailing slashes are required: location prefix and alias both end with /.
|
|
# Use the canonical shared storage tree so release switches do not break nginx.
|
|
# Do not use `root` here.
|
|
#
|
|
# Direct GET /internal/originals/... must 404 (internal;).
|
|
# Laravel still authorizes/counts; only the file body is offloaded.
|
|
|
|
location ^~ /internal/originals/ {
|
|
internal;
|
|
alias /opt/www/virtual/SkinbaseNova.releases/shared/storage/app/originals/artworks/;
|
|
}
|