That whole ESPAsyncWebServer github project has a lot of great examples on ways to use the esp8266.
Also, if you want to connect to your esp8266 externally, you can setup nginx (maybe on a raspberry pi?) as a reverse proxy with TLS enabled: https://jjssoftware.github.io/secure-your-esp8266/. Probably a bit pointless if you only have one esp8266 to connect to, since the RPi could probably do it all. But if you have multiple IoT devices to connect to, might be worth it.
Then your HTTP server can speak very little HTTP (compare request line to preformatted "GET /file HTTP/", return 404 on mismatch, return preformtted response on match). Maybe also return nice error if request does not have accept-encoding: gzip.
copy /b "%windir%\system32\extrac32.exe"+inputarchive.cab selfextract.exe