# nginx vhost for ModernSignal — adjust the domain, PHP-FPM socket path,
# and TLS cert paths (certbot fills those in automatically if you use
# `certbot --nginx`, so run certbot AFTER this file is in place and nginx
# has reloaded once on plain HTTP).
#
# Install: copy to /etc/nginx/sites-available/modernsignal.conf, then
#   sudo ln -s /etc/nginx/sites-available/modernsignal.conf /etc/nginx/sites-enabled/
#   sudo nginx -t && sudo systemctl reload nginx

server {
    listen 80;
    listen [::]:80;
    server_name yourdomain.com www.yourdomain.com;

    root /var/www/modernsignal/public;
    index index.php;

    add_header X-Frame-Options "SAMEORIGIN";
    add_header X-Content-Type-Options "nosniff";

    charset utf-8;

    location / {
        try_files $uri $uri/ /index.php?$query_string;
    }

    location = /favicon.ico { access_log off; log_not_found off; }
    location = /robots.txt  { access_log off; log_not_found off; }

    error_page 404 /index.php;

    location ~ \.php$ {
        fastcgi_pass unix:/run/php/php8.3-fpm.sock;
        fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
        include fastcgi_params;
    }

    # Built Vite assets — safe to cache aggressively, filenames are content-hashed.
    location /build/ {
        expires 1y;
        add_header Cache-Control "public, immutable";
    }

    location ~ /\.(?!well-known).* {
        deny all;
    }

    client_max_body_size 20M;
}
