# This folder is the document root: index.php here is the site's home page.
# Everything below protects the application internals that now live inside it.

DirectoryIndex index.php

# Primary protection: block the internal directories outright. This works even
# on hosts that ignore the per-directory .htaccess files in app/, config/, data/.
# manage-client/ is included: it is reached by PHP include only, never over HTTP
# — its backup and update functions are exposed through admin/maintenance.php,
# behind the admin login.
<IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteRule ^(app|config|data|docs|manage-client|migrations|scripts|client-package)/ - [F,L]
</IfModule>

# Cache static assets
<IfModule mod_expires.c>
    ExpiresActive On

    # CSS and JavaScript - 1 week
    ExpiresByType text/css "access plus 1 week"
    ExpiresByType application/javascript "access plus 1 week"
    ExpiresByType text/javascript "access plus 1 week"

    # Images - 4 weeks
    ExpiresByType image/jpeg "access plus 4 weeks"
    ExpiresByType image/gif "access plus 4 weeks"
    ExpiresByType image/png "access plus 4 weeks"
    ExpiresByType image/webp "access plus 4 weeks"
    ExpiresByType image/svg+xml "access plus 4 weeks"
</IfModule>

# Never serve dotfiles (.htaccess, .git*, …), flat-file data, docs, config
# templates or lock files as plain text — regardless of directory.
<FilesMatch "(^\.ht|^\.git|\.(?:json|md|lock|buf)$|\.sample\.php$)">
    Require all denied
</FilesMatch>

# Belt-and-suspenders for older Apache that lacks the FilesMatch above.
<IfModule !mod_authz_core.c>
    <FilesMatch "(^\.ht|^\.git|\.(?:json|md|lock|buf)$|\.sample\.php$)">
        Order allow,deny
        Deny from all
    </FilesMatch>
</IfModule>
