Skip to main content

Web Server, HTTPS, and Permissions

The client runs on a standard PHP 8.2 runtime. Choose one web server option and do not mix directives from different configurations.

Before configuration​

Replace the example domain, application path, PHP-FPM socket, and certificate paths. Point DNS to the server and verify HTTPS before opening the installer.

Option 1. Nginx + PHP-FPM​

nginx.conf
server {
listen 443 ssl http2;
server_name cabinet.example.com;
root /var/www/cabinet.example.com;
index index.php;

ssl_certificate /etc/letsencrypt/live/cabinet.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/cabinet.example.com/privkey.pem;
client_max_body_size 32m;

location / { try_files $uri $uri/ /index.php?$query_string; }
location ^~ /install/data/ { deny all; }
location ^~ /install/templates/ { deny all; }
location ^~ /internal_data/ { deny all; }
location ^~ /src/ { deny all; }
location ~ /\.(?!well-known) { deny all; }

location ~ \.php$ {
try_files $uri =404;
include fastcgi_params;
fastcgi_pass unix:/run/php/php8.2-fpm.sock;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param HTTPS on;
}
}

server {
listen 80;
server_name cabinet.example.com;
return 301 https://$host$request_uri;
}
Nginx check
sudo nginx -t
sudo systemctl reload nginx
curl -I https://cabinet.example.com/
curl -I https://cabinet.example.com/src/config.php

The protected path must return 403 or 404.

Option 2. Apache 2.4 + PHP-FPM​

Apache modules
sudo a2enmod rewrite proxy_fcgi setenvif headers ssl
sudo a2enconf php8.2-fpm
apache-vhost.conf
<VirtualHost *:443>
ServerName cabinet.example.com
DocumentRoot /var/www/cabinet.example.com

SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/cabinet.example.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/cabinet.example.com/privkey.pem

<Directory /var/www/cabinet.example.com>
Options -Indexes
AllowOverride All
Require all granted
</Directory>

<DirectoryMatch "^/var/www/cabinet\.example\.com/(src|internal_data|install/data|install/templates)(/|$)">
Require all denied
</DirectoryMatch>

ProxyPassMatch "^/(.*\.php)$" "unix:/run/php/php8.2-fpm.sock|fcgi://localhost/var/www/cabinet.example.com/"
LimitRequestBody 33554432
</VirtualHost>

<VirtualHost *:80>
ServerName cabinet.example.com
Redirect permanent / https://cabinet.example.com/
</VirtualHost>

The shipped root .htaccess routes requests to index.php.

Apache check
sudo apachectl configtest
sudo systemctl reload apache2

Option 3. LiteSpeed or OpenLiteSpeed​

Create a Virtual Host with /var/www/cabinet.example.com as its document root, enable rewrite and .htaccess, and connect PHP 8.2 through LiteSpeed SAPI. Add inaccessible contexts for:

OpenLiteSpeed protected contexts
/src/
/internal_data/
/install/data/
/install/templates/

Bind the domain to an HTTPS listener. After a graceful restart, verify /, /install/, and the blocked /src/config.php path.

Option 4. Caddy + FrankenPHP​

Caddyfile
cabinet.example.com {
root * /var/www/cabinet.example.com
encode zstd gzip

@protected path /src/* /internal_data/* /install/data/* /install/templates/*
respond @protected 404

@hidden path_regexp hidden (^|/)\.
respond @hidden 404

php_server

request_body {
max_size 32MB
}
}

Caddy obtains a TLS certificate automatically after DNS points to the server and ports 80/443 are reachable.

Reverse proxy and Cloudflare​

Use Full (strict), install an origin certificate, trust forwarding headers only from known proxy ranges, and bypass cache for /admin.php, /install/, /sign-in, /sign-up, /cabinet/, and POST requests.

File permissions​

File permissions
sudo chown -R app:www-data /var/www/cabinet.example.com
sudo find /var/www/cabinet.example.com -type d -exec chmod 750 {} \;
sudo find /var/www/cabinet.example.com -type f -exec chmod 640 {} \;
sudo chmod 600 /var/www/cabinet.example.com/src/config.php
sudo chmod -R u+rwX,g+rwX /var/www/cabinet.example.com/internal_data

The PHP user needs write access to internal_data, data, and product files replaced by one-click updates. Never use 777.

File permissions
- sudo chmod -R 777 /var/www/cabinet.example.com
+ sudo chown -R app:www-data /var/www/cabinet.example.com
+ sudo find /var/www/cabinet.example.com -type d -exec chmod 750 {} \;
+ sudo find /var/www/cabinet.example.com -type f -exec chmod 640 {} \;
+ sudo chmod 600 /var/www/cabinet.example.com/src/config.php

Final check​

  • HTTP redirects to HTTPS;
  • the certificate is valid;
  • / and /sign-in open;
  • /src/config.php and /internal_data/ return 403 or 404;
  • missing PHP scripts are not forwarded to PHP;
  • upload limits match in PHP and the web server;
  • the installer passes its permission check.