Options -Indexes -MultiViews

# Route all requests through index.php
<IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteBase /

    # Allow direct access to real files and directories
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d

    # Send everything else to index.php
    RewriteRule ^ index.php [QSA,L]
</IfModule>

# Security: block access to sensitive files
<FilesMatch "\.(env|log|sql|sh|bak|md|json|lock|xml|yml|yaml|ini|cfg)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order deny,allow
        Deny from all
    </IfModule>
</FilesMatch>

# Prevent access to dot-files
<FilesMatch "^\.">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
</FilesMatch>

# Compression
<IfModule mod_deflate.c>
    AddOutputFilterByType DEFLATE text/html text/css application/javascript application/json image/svg+xml
</IfModule>

# Cache static assets
<IfModule mod_expires.c>
    ExpiresActive On
    ExpiresByType text/css                  "access plus 1 year"
    ExpiresByType application/javascript    "access plus 1 year"
    ExpiresByType image/webp                "access plus 1 month"
    ExpiresByType image/svg+xml             "access plus 1 month"
    ExpiresByType font/woff2                "access plus 1 year"
</IfModule>

# Force HTTPS (uncomment when SSL is active)
# <IfModule mod_rewrite.c>
#     RewriteCond %{HTTPS} off
#     RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
# </IfModule>
