# Alternative to Caddy: Nginx catch-all. You must issue certificates per domain yourself
# (e.g. certbot --nginx -d register.hospital.com) whenever a hospital domain is mapped.
server {
    listen 80 default_server;
    listen [::]:80 default_server;
    server_name _;
    location /.well-known/acme-challenge/ { root /var/www/certbot; }
    location / { return 301 https://$host$request_uri; }
}

server {
    listen 443 ssl http2 default_server;
    server_name _;                       # catch-all: the app maps Host -> hospital
    ssl_certificate     /etc/ssl/carekiosk/fallback.crt;
    ssl_certificate_key /etc/ssl/carekiosk/fallback.key;

    root /var/www/carekiosk/public;
    index index.php;
    client_max_body_size 4m;

    location /assets/ { expires 7d; access_log off; }
    location ~ /\. { deny all; }
    location / { try_files $uri /index.php?$query_string; }
    location ~ \.php$ {
        include fastcgi_params;
        fastcgi_param SCRIPT_FILENAME $document_root/index.php;
        fastcgi_param HTTPS on;
        fastcgi_pass unix:/run/php/php8.3-fpm.sock;
    }
}
