Options -Indexes
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()"
Header always set Cross-Origin-Resource-Policy "same-origin"
RewriteEngine On
# Block hidden files/folders except ACME challenge path.
RewriteRule "(^|/)\.(?!well-known/)" - [F]
# Deny direct access to writable data files.
RewriteRule ^data/ - [F,L]
Require all denied
Order allow,deny
Deny from all