# Defence in depth for the upload directory.
#
# Uploads are already restricted to verified image types with a server-chosen
# extension, but this directory must never execute anything even if that check
# is bypassed or a file arrives some other way.

# Apache 2.4+
<IfModule mod_authz_core.c>
    <FilesMatch "\.(php|phar|phtml|php[0-9]|pl|py|cgi|asp|aspx|jsp|sh|htaccess)$">
        Require all denied
    </FilesMatch>
</IfModule>

# Apache 2.2
<IfModule !mod_authz_core.c>
    <FilesMatch "\.(php|phar|phtml|php[0-9]|pl|py|cgi|asp|aspx|jsp|sh|htaccess)$">
        Order allow,deny
        Deny from all
    </FilesMatch>
</IfModule>

# Belt and braces: strip any handler that would run these as code.
<IfModule mod_php.c>
    php_flag engine off
</IfModule>
<IfModule mod_php7.c>
    php_flag engine off
</IfModule>

RemoveHandler .php .phar .phtml .php3 .php4 .php5 .php7 .php8
RemoveType .php .phar .phtml .php3 .php4 .php5 .php7 .php8

<IfModule mod_headers.c>
    # Stop the browser guessing a different content type than we served.
    Header set X-Content-Type-Options "nosniff"

    # An uploaded SVG is same-origin markup. It is screened on upload, but
    # serving it under a locked-down CSP means a script that slips through
    # still cannot run.
    Header set Content-Security-Policy "default-src 'none'; img-src 'self' data:; style-src 'unsafe-inline'; sandbox"
</IfModule>

Options -Indexes -ExecCGI
