# =============================================================================
# Zimbabwe Cricket Safeguarding Platform — public_html/.htaccess
# =============================================================================

# --- Force HTTPS -------------------------------------------------------------
# Skipped for localhost/127.0.0.1 so local testing (XAMPP, MAMP, php -S, etc.)
# isn't broken by a redirect to https:// with no certificate behind it.
# Remove the RewriteCond lines once this is deployed under a real cPanel
# subdomain with SSL active, if you'd rather enforce HTTPS unconditionally.
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteCond %{HTTP_HOST} !^(localhost|127\.0\.0\.1)(:[0-9]+)?$
  RewriteCond %{HTTPS} off
  RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
</IfModule>

# --- Security headers ---------------------------------------------------------
<IfModule mod_headers.c>
  Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains"
  Header always set X-Content-Type-Options "nosniff"
  Header always set X-Frame-Options "DENY"
  Header always set Referrer-Policy "strict-origin-when-cross-origin"
  Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()"
  Header always set Content-Security-Policy "default-src 'self'; style-src 'self' 'unsafe-inline' fonts.googleapis.com; font-src fonts.gstatic.com; img-src 'self' data:; script-src 'self'; frame-ancestors 'none'"
</IfModule>

# --- Disable directory listing -------------------------------------------------
Options -Indexes -MultiViews

# --- Block direct access to sensitive files/extensions -------------------------
<FilesMatch "\.(env|ini|log|sql|md|lock|gitignore)$">
  Require all denied
</FilesMatch>

<FilesMatch "^(config|\.env)">
  Require all denied
</FilesMatch>

# Never serve PHP source from includes/ directly if someone guesses the path;
# these are only ever pulled in via require_once from a front controller.
<IfModule mod_rewrite.c>
  RewriteRule ^includes/ - [F,L]
</IfModule>

# --- Default document ----------------------------------------------------------
DirectoryIndex index.php

# --- Custom error handling (never leak stack traces / paths) -------------------
ErrorDocument 404 /index.php
ErrorDocument 500 /index.php
