{
    # Global options
    auto_https off
    admin off

    # Order directive for FrankenPHP
    order php_server before file_server
}

:80 {
    # Set root directory
    root * /app/public

    # Logging
    log {
        output stdout
        format console
        level INFO
    }

    # Encode responses
    encode gzip

    # Security headers
    header {
        X-Frame-Options "SAMEORIGIN"
        X-Content-Type-Options "nosniff"
        X-XSS-Protection "1; mode=block"
        Referrer-Policy "strict-origin-when-cross-origin"
    }

    # PHP + Laravel handling
    php_server
}
