Web Server, HTTPS, and Permissions
The client runs on a standard PHP 8.2 runtime. Choose one web server option and do not mix directives from different configurations.
Before configuration
Replace the example domain, application path, PHP-FPM socket, and certificate paths. Point DNS to the server and verify HTTPS before opening the installer.
Option 1. Nginx + PHP-FPM
server {
listen 443 ssl http2;
server_name cabinet.example.com;
root /var/www/cabinet.example.com;
index index.php;
ssl_certificate /etc/letsencrypt/live/cabinet.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/cabinet.example.com/privkey.pem;
client_max_body_size 32m;
location / { try_files $uri $uri/ /index.php?$query_string; }
location ^~ /install/data/ { deny all; }
location ^~ /install/templates/ { deny all; }
location ^~ /internal_data/ { deny all; }
location ^~ /src/ { deny all; }
location ~ /\.(?!well-known) { deny all; }
location ~ \.php$ {
try_files $uri =404;
include fastcgi_params;
fastcgi_pass unix:/run/php/php8.2-fpm.sock;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
fastcgi_param HTTPS on;
}
}
server {
listen 80;
server_name cabinet.example.com;
return 301 https://$host$request_uri;
}
sudo nginx -t
sudo systemctl reload nginx
curl -I https://cabinet.example.com/
curl -I https://cabinet.example.com/src/config.php
The protected path must return 403 or 404.
Option 2. Apache 2.4 + PHP-FPM
sudo a2enmod rewrite proxy_fcgi setenvif headers ssl
sudo a2enconf php8.2-fpm
<VirtualHost *:443>
ServerName cabinet.example.com
DocumentRoot /var/www/cabinet.example.com
SSLEngine on
SSLCertificateFile /etc/letsencrypt/live/cabinet.example.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/cabinet.example.com/privkey.pem
<Directory /var/www/cabinet.example.com>
Options -Indexes
AllowOverride All
Require all granted
</Directory>
<DirectoryMatch "^/var/www/cabinet\.example\.com/(src|internal_data|install/data|install/templates)(/|$)">
Require all denied
</DirectoryMatch>
ProxyPassMatch "^/(.*\.php)$" "unix:/run/php/php8.2-fpm.sock|fcgi://localhost/var/www/cabinet.example.com/"
LimitRequestBody 33554432
</VirtualHost>
<VirtualHost *:80>
ServerName cabinet.example.com
Redirect permanent / https://cabinet.example.com/
</VirtualHost>
The shipped root .htaccess routes requests to index.php.
sudo apachectl configtest
sudo systemctl reload apache2
Option 3. LiteSpeed or OpenLiteSpeed
Create a Virtual Host with /var/www/cabinet.example.com as its document root, enable rewrite and .htaccess, and connect PHP 8.2 through LiteSpeed SAPI. Add inaccessible contexts for:
/src/
/internal_data/
/install/data/
/install/templates/
Bind the domain to an HTTPS listener. After a graceful restart, verify /, /install/, and the blocked /src/config.php path.
Option 4. Caddy + FrankenPHP
cabinet.example.com {
root * /var/www/cabinet.example.com
encode zstd gzip
@protected path /src/* /internal_data/* /install/data/* /install/templates/*
respond @protected 404
@hidden path_regexp hidden (^|/)\.
respond @hidden 404
php_server
request_body {
max_size 32MB
}
}
Caddy obtains a TLS certificate automatically after DNS points to the server and ports 80/443 are reachable.
Reverse proxy and Cloudflare
Use Full (strict), install an origin certificate, trust forwarding headers only from known proxy ranges, and bypass cache for /admin.php, /install/, /sign-in, /sign-up, /cabinet/, and POST requests.
File permissions
sudo chown -R app:www-data /var/www/cabinet.example.com
sudo find /var/www/cabinet.example.com -type d -exec chmod 750 {} \;
sudo find /var/www/cabinet.example.com -type f -exec chmod 640 {} \;
sudo chmod 600 /var/www/cabinet.example.com/src/config.php
sudo chmod -R u+rwX,g+rwX /var/www/cabinet.example.com/internal_data
The PHP user needs write access to internal_data, data, and product files replaced by one-click updates. Never use 777.
- sudo chmod -R 777 /var/www/cabinet.example.com
+ sudo chown -R app:www-data /var/www/cabinet.example.com
+ sudo find /var/www/cabinet.example.com -type d -exec chmod 750 {} \;
+ sudo find /var/www/cabinet.example.com -type f -exec chmod 640 {} \;
+ sudo chmod 600 /var/www/cabinet.example.com/src/config.php
Final check
- HTTP redirects to HTTPS;
- the certificate is valid;
/and/sign-inopen;/src/config.phpand/internal_data/return403or404;- missing PHP scripts are not forwarded to PHP;
- upload limits match in PHP and the web server;
- the installer passes its permission check.