Hi there,

> while i request files
> http://domain.com/config.xml
> or
> http://domain.com/include/config.xml
> both files downloaded, which is not good,

When I do it:

$ curl
Did match: /config.xml
$ curl
Did not match: /include/config.xml

The first matches (and so is blocked), and the second does not match
(and so it allowed). I think that that is what you want?

Either you are not using the configuration you think you are using;
or you have other configuration that you are not showing.

