Deny access to all dot files and dirs by default (except .well-known) Update nginx rules accordingly and pass denied requests to Pico rather than letting nginx send a 404 response