Skip to content

Consider putting public-facing files in a public folder instead of mixing with application files #935

Description

@lautriva

LinkStack version

4.8.4

Description

Having all assets + index.php in a public folder then the webserver pointing to this public folder would remove the need to add custom rules to protect application + sensitive files in .htaccess (those are not read by nginx and caddy)

This is the recommended Laravel structure

Details about your system

Linkstack installed on server using Caddy + PHP (without using docker)

How to reproduce

Install Linkstack on a caddy server

Possible Solution

@block_files expression path_regexp('\\..*') || path_regexp('.*\\.sqlite')
respond @block_files 403

Additional Context

No response

Activity

  1. thedod commented on Feb 18, 2026

    @thedod

    Specifically, database/database.sqlite shouldn't be accessible from web. It's true that you provide a .htaccess file that blocks access to it, but I'm using a shared nginx host that ignores .htaccess, and doesn't let me configure denial of web access to files in any other way.

  2. dezfutak commented on Apr 7, 2026

    @dezfutak

    Specifically, database/database.sqlite shouldn't be accessible from web. It's true that you provide a .htaccess file that blocks access to it, but I'm using a shared nginx host that ignores .htaccess, and doesn't let me configure denial of web access to files in any other way.

    Workaraound - add the following to your existing domain.conf entry in /etc/nginx/sites-enabled/ :

    # Deny access to hidden files, except .well-known if you use it
        location ~ /\.(?!well-known/) {
            deny all;
            access_log off;
            log_not_found off;
        }
    
        # Deny access to sqlite and zip files
        location ~* \.(sqlite|zip)$ {
            deny all;
            access_log off;
            log_not_found off;
        }
    
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions