# Nginx (alternative to Caddy). Point all society domains to this server block.
# SSL: wildcard cert for *.platform via certbot DNS challenge, plus `certbot --nginx -d www.society.com` per custom domain.
server {
    listen 80 default_server;
    listen 443 ssl http2 default_server;
    server_name _;
    root /var/www/coopsaas/public;
    index index.php;
    client_max_body_size 10M;

    ssl_certificate     /etc/letsencrypt/live/sahakarcloud.in/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/sahakarcloud.in/privkey.pem;

    if ($scheme = http) { return 301 https://$host$request_uri; }

    location ~ ^/(install|router|tls-check)\.php$ { deny all; }
    location / { try_files $uri /index.php?$query_string; }
    location ~ \.php$ {
        include fastcgi_params;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        fastcgi_param HTTPS on;
        fastcgi_pass unix:/run/php/php8.3-fpm.sock;
    }
    location ~ /\. { deny all; }
}
