If I had to guess, this person committed their .env file in some repo and pushed that up, and that become available because the server was misconfigured.
For other servers (such as, say, Jetty), config files like that won't get exposed like that unless you're very obviously placing your config files in a public resource folder.
The server software reads the config file and then decides if the folder can be accessed externally or not.
It has nothing to do with PHP what framework or any other language you are running.
Yup. That's why I am saying that in the past .htaccess used to be used, but modern php frameworks no longer rely on it. Poor phrasing on my end.
Every other language acts as its own web server which wouldn't even be capable of serving files even if you tried; the only thing it does is respond to web routes defined by the application.
This eliminates a whole chunk of security issues, from the one described above to malicious file uploads (PHP is probably the only language where a malicious file upload leads to RCE by default - other languages could happily accept and serve the malicious file back but wouldn't execute it).
A non issue though after 2-3 days of working with this approach. All modern PHP frameworks have a so called front controller (an index.php file) that loads what it requires from ../ after, ideally, properly validating the request to avoid issues.
Tell that to all the people with bleeding feet.
The only way to avoid to have the server open only to you till everything is tied down right and the backend is ready to face the world.
To rely upon being quicker on the draw than the bots is quite courageous.