# Disable directory browsing
Options All -Indexes

# PHP upload limits
php_value upload_max_filesize 12M
php_value post_max_size 16M

# ----------------------------------------------------------------------
# Rewrite engine
# ----------------------------------------------------------------------

# Turning on the rewrite engine is necessary for the following rules and features.
# FollowSymLinks must be enabled for this to work.
<IfModule mod_rewrite.c>
	Options +FollowSymlinks
	RewriteEngine On

	# If you installed CodeIgniter in a subfolder, you will need to
	# change the following line to match the subfolder you need.
	# http://httpd.apache.org/docs/current/mod/mod_rewrite.html#rewritebase
	# RewriteBase /

	# Block view-source access
	RewriteCond %{THE_REQUEST} view-source: [NC]
	RewriteRule ^ - [F,L]

	# Redirect Trailing Slashes...
	RewriteCond %{REQUEST_FILENAME} !-d
	RewriteCond %{REQUEST_URI} (.+)/$
	RewriteRule ^ %1 [L,R=301]

	# Rewrite "www.example.com -> example.com"
	RewriteCond %{HTTPS} !=on
	RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
	RewriteRule ^ http://%1%{REQUEST_URI} [R=301,L]

	# Checks to see if the user is attempting to access a valid file,
	# such as an image or css document, if this isn't true it sends the
	# request to the front controller, index.php
	RewriteCond %{REQUEST_FILENAME} !-f
	RewriteCond %{REQUEST_FILENAME} !-d
	RewriteRule ^([\s\S]*)$ index.php/$1 [L,NC,QSA]

	# Ensure Authorization header is passed along
	RewriteCond %{HTTP:Authorization} .
	RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

	# Prevent direct access to PHP files in the system directory
	RewriteRule ^(system) - [F,L]
</IfModule>

<IfModule !mod_rewrite.c>
	# If we don't have mod_rewrite installed, all 404's
	# can be sent to index.php, and everything works as normal.
	ErrorDocument 404 index.php
</IfModule>

# Disable server signature start
ServerSignature Off
# Disable server signature end

# Prevent direct access to certain file types
<FilesMatch "(?i)\.(php|php3?|phtml|phps)$">
	Order Deny,Allow
	Deny from all
</FilesMatch>

# Allow direct access only to index.php
<Files index.php>
	Order Allow,Deny
	Allow from all
</Files>

# Additional security headers
<IfModule mod_headers.c>
	Header set X-Frame-Options "SAMEORIGIN"
	Header set X-XSS-Protection "1; mode=block"
	Header set X-Content-Type-Options "nosniff"
	Header set Content-Security-Policy "default-src 'self' data: blob:; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdnjs.cloudflare.com https://cdn.jsdelivr.net https://cdn.tiny.cloud https://js.hcaptcha.com https://newassets.hcaptcha.com; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://cdnjs.cloudflare.com https://fonts.googleapis.com https://newassets.hcaptcha.com; img-src 'self' data: blob: https: http:; font-src 'self' data: https:; connect-src 'self' https: blob:; frame-src 'self' https:; worker-src 'self' blob:;"
	# Prevent browsers from MIME-sniffing the content-type
	Header set X-Content-Type-Options "nosniff"
	# Don't allow pages to be embedded in frames
	Header set X-Frame-Options "DENY"
	# Enable the XSS filter built into modern web browsers
	Header set X-XSS-Protection "1; mode=block"
	# Disable some features that could be exploited
	Header set Referrer-Policy "strict-origin-when-cross-origin"
	Header set Permissions-Policy "geolocation=(), midi=(), sync-xhr=(), microphone=(), camera=(self), magnetometer=(), gyroscope=(), fullscreen=(self), payment=()"
</IfModule>