# Enable URL rewriting
<IfModule mod_rewrite.c>
  RewriteEngine On

  # Serve existing files directly (CSS, JS, images, uploads)
  RewriteCond %{REQUEST_FILENAME} -f [OR]
  RewriteCond %{REQUEST_FILENAME} -d
  RewriteRule ^ - [L]

  # Route everything else through index.php (front controller)
  RewriteRule ^ index.php [L]
</IfModule>

# Prevent direct access to sensitive files
<FilesMatch "\.(sql|md|env|json)$">
  Require all denied
</FilesMatch>

# Hide .htaccess itself
<Files ".htaccess">
  Require all denied
</Files>

# Disable directory listing
Options -Indexes

# Set default charset
AddDefaultCharset UTF-8

# Security headers
<IfModule mod_headers.c>
  Header set X-Content-Type-Options "nosniff"
  Header set X-Frame-Options "SAMEORIGIN"
  Header set X-XSS-Protection "1; mode=block"
  Header set Referrer-Policy "strict-origin-when-cross-origin"
</IfModule>

# Max upload size (must be ≥ PHP post_max_size + upload_max_filesize)
<IfModule mod_php.c>
  php_value upload_max_filesize 10M
  php_value post_max_size 12M
</IfModule>
