# ICSSPK Events - public/.htaccess (Apache / cPanel)
#
# public/ is the ONLY web-exposed directory. Everything else (app/, config/,
# storage/, .env ...) lives outside the document root; this file does not
# "hide" them, it only routes requests and hardens what is public.
#
# If your host returns "500 Internal Server Error" because it forbids the
# Options directive, delete the "Options -Indexes" line below.

Options -Indexes
DirectoryIndex index.php

# ---------- Front controller ----------
<IfModule mod_rewrite.c>
    RewriteEngine On

    # Installed in a sub-folder? Uncomment and set it, e.g. RewriteBase /events/
    # RewriteBase /

    # Block dotfiles (.env, .user.ini, .git ...) except ACME challenges.
    RewriteRule (^|/)\.(?!well-known/) - [F,L]

    # Serve real files (assets, uploaded media) directly.
    RewriteCond %{REQUEST_FILENAME} -f
    RewriteRule ^ - [L]

    # Everything else goes to the application.
    RewriteRule ^ index.php [L]
</IfModule>
# Without mod_rewrite the app still works at /index.php/awards/... (PATH_INFO).

# ---------- Only index.php may execute ----------
<IfModule mod_authz_core.c>
    <FilesMatch "\.(?i:php\d?|phtml|phar)$">
        Require all denied
    </FilesMatch>
    <Files "index.php">
        Require all granted
    </Files>
    <FilesMatch "(?i)\.(env|ini|log|sql|md|example|bak|old|orig|swp|dist|lock|ya?ml|sh|json)$">
        Require all denied
    </FilesMatch>
</IfModule>

# ---------- Security headers for static files ----------
# (the application sets its own full header set, including CSP)
<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set X-Frame-Options "DENY"
    Header always unset X-Powered-By
    Header unset X-Powered-By
</IfModule>

# ---------- Compression ----------
<IfModule mod_deflate.c>
    AddOutputFilterByType DEFLATE text/html text/css text/plain text/xml application/xml application/javascript application/json image/svg+xml font/woff
</IfModule>

# ---------- Browser caching (asset URLs carry ?v=<mtime>, so long caching is safe) ----------
<IfModule mod_expires.c>
    ExpiresActive On
    ExpiresByType text/css "access plus 1 year"
    ExpiresByType application/javascript "access plus 1 year"
    ExpiresByType text/javascript "access plus 1 year"
    ExpiresByType font/woff "access plus 1 year"
    ExpiresByType font/woff2 "access plus 1 year"
    ExpiresByType application/font-woff "access plus 1 year"
    ExpiresByType font/ttf "access plus 1 year"
    ExpiresByType image/png "access plus 1 month"
    ExpiresByType image/jpeg "access plus 1 month"
    ExpiresByType image/webp "access plus 1 month"
    ExpiresByType image/svg+xml "access plus 1 month"
    ExpiresByType image/x-icon "access plus 1 month"
</IfModule>

<IfModule mod_php.c>
    php_flag display_errors Off
    php_flag expose_php Off
</IfModule>
