# =====================================================================
# CRITICAL SECURITY FILE — do not remove.
#
# This is the fix for the exact vulnerability that caused the last
# compromise: a user could upload a file named e.g. "shell.php" into
# this folder and then simply visit it in a browser to have the
# server execute it. This file stops that, even if the application
# code that validates uploads is ever changed or has a bug, and even
# for sub-folders created automatically at runtime (Apache applies
# .htaccess rules to every subdirectory beneath this one).
#
# Everything in uploads/ should be a downloadable document, image, or
# media file — never something the server executes.
# =====================================================================

# Belt-and-braces: disable the PHP engine for this directory tree on
# hosts using mod_php.
<IfModule mod_php.c>
    php_flag engine off
</IfModule>
<IfModule mod_php7.c>
    php_flag engine off
</IfModule>
<IfModule mod_php8.c>
    php_flag engine off
</IfModule>

# Explicitly refuse to execute PHP (and other server-side/script)
# files no matter how the handler is configured (works for
# mod_php, PHP-FPM via handler/action, CGI, and suEXEC setups).
<FilesMatch "\.(php|php3|php4|php5|php7|phtml|pht|phar|cgi|pl|py|sh|asp|aspx|jsp|jspx|exe|dll)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

# Remove any handler mapping that would otherwise cause these
# extensions to be executed by the server in this directory tree.
RemoveHandler .php .php3 .php4 .php5 .php7 .phtml .pht .phar .cgi .pl .py .sh
RemoveType .php .php3 .php4 .php5 .php7 .phtml .pht .phar .cgi .pl .py .sh

# No directory listings.
Options -Indexes -ExecCGI
