# Laravel shared-hosting rewrite - fixed to avoid 500 on cPanel/LiteSpeed
<IfModule mod_rewrite.c>
    RewriteEngine On

    # Send all requests to Laravel public folder without exposing /public in URL
    RewriteCond %{REQUEST_URI} !^/public/
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule ^(.*)$ public/$1 [L]

    # Homepage
    RewriteRule ^$ public/index.php [L]
</IfModule>

# Protect sensitive Laravel/source files. Uses Apache 2.4 syntax when available.
<FilesMatch "^(\.env|\.git|\.htaccess|composer\.(json|lock)|package(-lock)?\.json|yarn\.lock|artisan|phpunit\.xml|.*\.sql|.*\.log)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

# Block direct access to Laravel system folders
<IfModule mod_alias.c>
    RedirectMatch 404 ^/(app|bootstrap|config|database|resources|routes|storage|tests|vendor)/.*$
</IfModule>

# Security response headers (safe baseline for shared hosting)
<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"
    Header always set Content-Security-Policy "frame-ancestors 'self'; object-src 'none'; base-uri 'self'"
    Header always unset X-Powered-By
</IfModule>

