#sub_path_only rewrite ^__PATH__$ __PATH__/ permanent; location __PATH__/ { alias __INSTALL_DIR__/; if (!-e $request_filename) { rewrite ^(.*)$ /index.php?req=$1; } client_max_body_size 50m; client_body_buffer_size 128k; # Default indexes and catch-all index index.php; charset utf-8; location ~* \.php$ { try_files $uri =404; fastcgi_pass unix:/var/run/php/php__PHPVERSION__-fpm-__NAME__.sock; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } # make sure webfinger and other well known services aren't blocked # by denying dot files and rewrite request to the front controller location ^~ /.well-known/ { allow all; if (!-e $request_filename) { rewrite ^(.*)$ /index.php?req=$1; } } # block these file types location ~* \.(tpl|md|tgz|log|out)$ { deny all; } # deny access to all dot files location ~ /\. { deny all; } #deny access to store location ~ /store { deny all; } #deny access to util location ~ /util { deny all; } }