# =====================================================================
# SECURITY HARDENING — root .htaccess
# =====================================================================

# --- Force HTTPS (uncomment once your SSL certificate is active) ---
# RewriteEngine On
# RewriteCond %{HTTPS} off
# RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

# --- Security headers ---
<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set X-XSS-Protection "1; mode=block"
    Header unset X-Powered-By
</IfModule>
<IfModule mod_setenvif.c>
    ServerSignature Off
</IfModule>

# --- Never allow directory listing ---
Options -Indexes

# --- Block access to sensitive file types anywhere in this app ---
<FilesMatch "\.(sql|log|md|env|ini|bak|sh|git)$">
    Require all denied
</FilesMatch>

# --- Block dotfiles (.git, .htaccess itself viewed as text, etc.) ---
<FilesMatch "^\.">
    Require all denied
</FilesMatch>
