# ============================================================
# Spartan Fitness OS - Apache/Cpanel hosting hardening + routing
# ============================================================

# --- General hardening ---
Options -Indexes
ServerSignature Off

# --- Block directory listing & common hosts probing (wp, backups) ---
<FilesMatch "^(\.env.*|\.git.*|\.htaccess|\.htpasswd|composer\.(json|lock)|package.json|package-lock.json|pubspec.lock|yarn.lock)$">
    Require all denied
</FilesMatch>

# --- CLI-only maintenance scripts must never be reachable over HTTP ---
<FilesMatch "^(fix_permissions\.php|router\.php|error_404\.php)$">
    Require all denied
</FilesMatch>

<IfModule mod_rewrite.c>
    RewriteEngine On

    # --- 403 on sensitive folders/files ---
    RewriteRule ^\.env - [F,L]
    RewriteRule ^logs/ - [F,L]
    RewriteRule ^storage/ - [F,L]
    RewriteRule ^includes/ - [F,L]
    RewriteRule ^app/ - [F,L]
    RewriteRule ^DB/ - [F,L]
    RewriteRule ^vendor/ - [F,L]
    # Flutter source trees. Both the current name and the legacy name are
    # blocked: the folder was renamed and the stale entry alone left the whole
    # Dart source (including the API host) publicly readable.
    RewriteRule ^spartan_warrior_fitness_gym_app/ - [F,L]
    RewriteRule ^Spartan_Fitness_night/ - [F,L]
    RewriteRule ^(composer\.json|composer\.lock|package\.json|package-lock\.json|pubspec\.lock|yarn\.lock)$ - [F,L]

    # --- Pages and auth scripts are only ever reached through index.php ---
    # They are included on the filesystem, never requested directly, so serving
    # them over HTTP would bypass the login/permission map in index.php.
    RewriteRule ^pages/ - [F,L]
    RewriteRule ^auth/ - [F,L]

    # --- API: route /api/xxx to api/xxx.php (physical files, not in the route map) ---
    RewriteRule ^api/([a-zA-Z0-9_]+)$ api/$1.php [L]

    # --- Pretty URLs: route everything that is not a real file/dir through index.php ---
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule ^(.*)$ index.php?url=$1 [QSA,L]
</IfModule>

# --- Basic security headers ---
<IfModule mod_headers.c>
    Header set X-Content-Type-Options "nosniff"
    Header set X-Frame-Options "SAMEORIGIN"
    Header set Referrer-Policy "strict-origin-when-cross-origin"
</IfModule>

# php -- BEGIN cPanel-generated handler, do not edit
# Set the “ea-php81” package as the default “PHP” programming language.
<IfModule mime_module>
  AddHandler application/x-httpd-ea-php81 .php .php8 .phtml
</IfModule>
# php -- END cPanel-generated handler, do not edit
