# ============================================================
# public/uploads - user-supplied files ONLY.
#
# Nothing in this tree may ever be executed. Every file here is
# either an image or a document that was uploaded by a member or
# an admin, so any script that lands here (including one smuggled
# in through an upload form) must be served as inert content.
# ============================================================

Options -Indexes
ServerSignature Off

# --- Deny every executable/script handler ---
<IfModule mod_php.c>
  php_flag engine off
</IfModule>
<IfModule mod_php7.c>
  php_flag engine off
</IfModule>
<IfModule mod_php8.c>
  php_flag engine off
</IfModule>

# Belt-and-braces: strip any handler that a parent directory or a
# AddHandler/AddType directive may have associated with these files.
<FilesMatch "\.(?i:php|php[0-9]|phtml|phps|phar|cgi|pl|py|sh|bash|asp|aspx|jsp|htaccess)$">
  Require all denied
</FilesMatch>

# Remove inherited PHP handlers for common script extensions.
<IfModule mod_mime.c>
  RemoveHandler .php .php3 .php4 .php5 .php7 .php8 .phtml .phar
  RemoveType .php .php3 .php4 .php5 .php7 .php8 .phtml .phar
</IfModule>

# --- Never let the server infer a content type from a file that
#     is not a genuine image ---
<IfModule mod_headers.c>
  Header set X-Content-Type-Options "nosniff"
  Header set Content-Disposition "inline"
</IfModule>
