diff --git a/setup/configuration.md b/setup/configuration.md
index 8c334600..ce0d7ac5 100644
--- a/setup/configuration.md
+++ b/setup/configuration.md
@@ -47,7 +47,9 @@ location / {
rewrite ^/.*$ /index.php last;
}
-# Pass the PHP scripts to FastCGI server
+# Pass the PHP scripts to FastCGI server.
+# Note this matches `/index.php` only, and deliberately so: it is what stops any other PHP
+# file in the document root from being executed. Do not broaden it to `location ~ \.php$`.
location ~ ^/index.php {
# Write your FPM configuration here
@@ -137,6 +139,10 @@ $HTTP["host"] =~ "domain.example.com" {
# - /storage/temp/public: Public temporary files
# Note: /storage/app/uploads/protected is NOT exposed here
url.rewrite-once = (
+ # Block all PHP files, except index. This must come first: the passthrough rules
+ # below serve their paths as-is, so without this a PHP file written anywhere under
+ # them would be handed to the PHP handler.
+ "^/(?!index\.php(\?.*|)$).*\.php(\?.*|)$" => "/index.php",
"^/(plugins|modules/(system|backend|cms))/(([\w-]+/)+|/|)assets/([\w-]+/)+[-\w^&'@{}[\],$=!#().%+~/ ]+\.(jpg|jpeg|gif|png|svg|swf|avi|mpg|mpeg|mp3|flv|ico|css|js|woff|ttf)(\?.*|)$" => "$0",
"^/(system|themes/[\w-]+)/assets/([\w-]+/)+[-\w^&'@{}[\],$=!#().%+~/ ]+\.(jpg|jpeg|gif|png|svg|swf|avi|mpg|mpeg|mp3|flv|ico|css|js|woff|ttf)(\?.*|)$" => "$0",
"^/storage/app/uploads/public/[\w-]+/.*$" => "$0",
@@ -167,6 +173,20 @@ If your webserver is running Internet Information Services (IIS) you can use the
- /storage/temp/public: Public temporary files
Note: /storage/app/uploads/protected is NOT exposed here
-->
+
+
+
+
+
+
+
+
+