Options -Indexes
RewriteEngine On

# Force HTTPS when the host/proxy exposes the protocol header.
RewriteCond %{HTTPS} !=on
RewriteCond %{HTTP:X-Forwarded-Proto} !https [NC]
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

# Protect private application files when this package is deployed as a single folder.
RewriteRule ^(?:src|data|scripts|templates)/ - [F,L]
RewriteRule ^(?:config\.php|config\.example\.php|install\.sql|README\.md|PRODUCTION-CHECKLIST\.md)$ - [F,L]

RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^ index.php [QSA,L]

<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Permissions-Policy "geolocation=(), camera=(), microphone=()"
</IfModule>

<IfModule mod_expires.c>
ExpiresActive On
ExpiresByType text/css "access plus 7 days"
ExpiresByType image/svg+xml "access plus 30 days"
</IfModule>

<FilesMatch "^(config(?:\.example)?\.php|install\.sql|README\.md|PRODUCTION-CHECKLIST\.md)$">
Require all denied
</FilesMatch>
