Options -MultiViews
DirectorySlash Off

RewriteEngine On

# Teacher login API (old clean URL) - must come BEFORE the pass-through below
RewriteRule ^teachers/teacher_apis/teacher_login/?$ teachers/teacher_apis/teacher_login_api.php [L]

# API (/api/ and the teacher app): hand the Authorization header to PHP...
RewriteCond %{REQUEST_URI} ^/(api|teachers/teacher_apis)/
RewriteCond %{HTTP:Authorization} .
RewriteRule ^ - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

# ...and never rewrite / redirect anything below them (a 301 turns the app's POST into an empty reply)
RewriteCond %{REQUEST_URI} ^/(api|teachers/teacher_apis)/
RewriteRule ^ - [L]

# Clean URL -> PHP file
RewriteCond %{DOCUMENT_ROOT}/%{REQUEST_URI}.php -f
RewriteRule ^(.+?)/?$ $1.php [L]

# Normal website: PHP -> clean URL
RewriteCond %{REQUEST_URI} !^/api/
RewriteCond %{REQUEST_URI} !^/teachers/teacher_apis/
RewriteCond %{THE_REQUEST} \s/+(.+?)\.php[\s?] [NC]
RewriteRule ^ /%1 [R=301,L]

# Security hardening... (keep whatever else you already have here)
Options -Indexes
