Options -MultiViews
DirectorySlash Off

RewriteEngine On

# ============================================
# API: Never redirect .php files
# ============================================
RewriteCond %{REQUEST_URI} ^/api/
RewriteCond %{HTTP:Authorization} .
RewriteRule ^ - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

RewriteCond %{REQUEST_URI} ^/api/
RewriteRule ^ - [L]

# ============================================
# Clean URL -> PHP file
# Example:
# /api/v1/auth/student_login
# -> /api/v1/auth/student_login.php
# ============================================
RewriteCond %{DOCUMENT_ROOT}/%{REQUEST_URI}.php -f
RewriteRule ^(.+?)/?$ $1.php [L]

# ============================================
# Teacher login API
# ============================================
RewriteRule ^teachers/teacher_apis/teacher_login/?$ teachers/teacher_apis/teacher_login_api.php [L]
# ============================================
# Normal website: PHP -> clean URL
# Do NOT apply this to /api/
# ============================================
RewriteCond %{REQUEST_URI} !^/api/
RewriteCond %{THE_REQUEST} \s/+(.+?)\.php[\s?] [NC]
RewriteRule ^ /%1 [R=301,L]

# ============================================
# SECURITY HARDENING (added after the 2026-09 compromise)
# ============================================

# Never list directory contents.
Options -Indexes

# Never serve database dumps, backup archives, dev scripts, version
# control data, or environment files, no matter where they end up in
# the tree. These should never be inside the web root at all — see
# the accompanying security report — but this is a second layer of
# defence in case one is added back by mistake.
<FilesMatch "\.(sql|sqlite|bak|backup|old|orig|swp|log|env|ini|py|rar|7z|tar|gz|zip)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

<FilesMatch "^\.">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

# Basic security response headers.
<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
</IfModule>


# Block dependency/manifests from public access
<FilesMatch "^(composer\.json|composer\.lock|package\.json|package-lock\.json|yarn\.lock|pnpm-lock\.yaml)$">
    Require all denied
</FilesMatch>
