# Fallback protection for the project root.
#
# The document root is meant to point at `public/`, in which case this file is
# never consulted. It exists because pointing a vhost (or htdocs) at the
# project root instead is an easy mistake, and that would otherwise expose
# .env, the source under app/, and the logs under storage/.

<IfModule mod_rewrite.c>
    RewriteEngine On

    # Route everything through the real front controller.
    RewriteCond %{REQUEST_URI} !^/public/
    RewriteRule ^(.*)$ public/$1 [L]
</IfModule>

# Deny the directories that must never be served, whatever the docroot is.
RedirectMatch 404 ^/(?:app|config|database|resources|storage)(?:/|$)

# Dotfiles, starting with .env.
<FilesMatch "^\.">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

<FilesMatch "\.(env|log|sql|md|bat)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

Options -Indexes
