# Uploaded images only. Nothing in this directory may ever execute.
#  - PHP/CGI handlers removed and script extensions denied outright
#  - only .jpg/.jpeg/.png/.webp are served at all
#  - a sandboxing CSP means even a disguised file cannot run script
# Uploads are additionally re-encoded through GD with random filenames (Phase 4).

<IfModule mod_php.c>
    php_flag engine off
</IfModule>
RemoveHandler .php .php3 .php4 .php5 .php7 .php8 .phtml .phar .pl .py .cgi .sh .shtml
RemoveType .php .php3 .php4 .php5 .php7 .php8 .phtml .phar

<IfModule mod_authz_core.c>
    Require all denied
    <FilesMatch "(?i)^[a-z0-9_\-]+\.(jpe?g|png|webp)$">
        Require all granted
    </FilesMatch>
</IfModule>

<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set Content-Security-Policy "default-src 'none'; img-src 'self'; sandbox"
</IfModule>
