# Disable directory browsing
Options -Indexes

# ----------------------------------------------------------------------
# Rewrite engine
# ----------------------------------------------------------------------

# Turning on the rewrite engine is necessary for the following rules and features.
# FollowSymLinks must be enabled for this to work.
<IfModule mod_rewrite.c>
	Options +FollowSymlinks
	RewriteEngine On

	# Force HTTPS outside local development. This keeps the host requested by
	# cPanel and avoids redirecting localhost while testing the project.
	RewriteCond %{HTTPS} !=on
	RewriteCond %{HTTP_HOST} !^(localhost|127\.0\.0\.1)(:[0-9]+)?$ [NC]
	RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]

	# If you installed CodeIgniter in a subfolder, you will need to
	# change the following line to match the subfolder you need.
	# http://httpd.apache.org/docs/current/mod/mod_rewrite.html#rewritebase
	# RewriteBase /

	# Redirect Trailing Slashes...
	RewriteCond %{REQUEST_FILENAME} !-d
	RewriteCond %{REQUEST_URI} (.+)/$
	RewriteRule ^ %1 [L,R=301]

	# Checks to see if the user is attempting to access a valid file,
	# such as an image or css document, if this isn't true it sends the
	# request to the front controller, index.php
	RewriteCond %{REQUEST_FILENAME} !-f
	RewriteCond %{REQUEST_FILENAME} !-d
	RewriteRule ^([\s\S]*)$ index.php/$1 [L,NC,QSA]

	# Ensure Authorization header is passed along
	RewriteCond %{HTTP:Authorization} .
	RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
</IfModule>

<IfModule !mod_rewrite.c>
	# If we don't have mod_rewrite installed, all 404's
	# can be sent to index.php, and everything works as normal.
	ErrorDocument 404 index.php
</IfModule>

# Disable server signature start
ServerSignature Off
# Disable server signature end

# Production security headers that do not interfere with Stripe Checkout or
# the external Bootstrap and Google Fonts assets used by the landing page.
<IfModule mod_headers.c>
	Header always set X-Content-Type-Options "nosniff"
	Header always set X-Frame-Options "SAMEORIGIN"
	Header always set Referrer-Policy "strict-origin-when-cross-origin"
	Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"
</IfModule>

# Cache versioned/static assets in the visitor's browser. HTML responses are
# left uncached so pricing and countdown changes are visible immediately.
<IfModule mod_expires.c>
	ExpiresActive On
	ExpiresByType text/css "access plus 7 days"
	ExpiresByType application/javascript "access plus 7 days"
	ExpiresByType image/png "access plus 30 days"
	ExpiresByType image/x-icon "access plus 30 days"
	ExpiresByType application/pdf "access plus 7 days"
</IfModule>
