# LockChat / SandiChat 1.1.4 — Apache / LiteSpeed (cPanel, CWP, DirectAdmin, aaPanel, ...)
# Every block is optional: if a module is missing, the line is skipped (no 500 error).

DirectoryIndex index.php

# Force HTTPS
<IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteCond %{HTTPS} !=on
    RewriteCond %{HTTP:X-Forwarded-Proto} !=https
    RewriteCond %{HTTP:CF-Visitor} !"scheme\":\"https"
    RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    # Internal folders/files are never served directly
    RewriteRule ^(data|inc)(/|$) - [F,L]
    RewriteRule (^|/)(config\.php|cron\.php|README\.md|node\.json)$ - [F,L]
    RewriteRule \.(sqlite|sqlite-wal|sqlite-shm|bak)$ - [F,L]
    # 1.1.4: alamat tanpa .php (mis. halaman admin rahasia) diteruskan ke index.php
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule ^[A-Za-z0-9_-]+/?$ index.php [L,QSA]
</IfModule>

# Same protection without mod_rewrite (Apache 2.4 + 2.2 syntax)
<FilesMatch "^(config\.php|cron\.php|README\.md|node\.json|.*\.sqlite.*)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

<IfModule mod_mime.c>
    AddType application/manifest+json .webmanifest
    AddType application/javascript .js
    AddType font/woff2 .woff2
</IfModule>

<IfModule mod_headers.c>
    <FilesMatch "^sw\.js$">
        Header set Cache-Control "no-cache"
    </FilesMatch>
    Header always set X-Content-Type-Options "nosniff"
    Header always set Referrer-Policy "no-referrer"
</IfModule>

<IfModule mod_expires.c>
    ExpiresActive On
    ExpiresByType text/css "access plus 7 days"
    ExpiresByType application/javascript "access plus 7 days"
    ExpiresByType font/woff2 "access plus 30 days"
</IfModule>
