# ============================================================================= # OPTION B — front controller AT the app root # # Use this only when index.php and assets/ sit DIRECTLY in the app folder, # i.e. the contents of the package public/ folder were moved up one level: # # public_html/aiseo/index.php # public_html/aiseo/assets/ # public_html/aiseo/bootstrap.php # public_html/aiseo/3-source-code/src/ # # Save it as .htaccess in that folder. No RewriteBase needed. # # Verified against real Apache 2.4: # /aiseo/ 200 /aiseo/.env 403 # /aiseo/integrations 200 /aiseo/bootstrap.php 403 # /aiseo/assets/css/tokens.css 200 /aiseo/3-source-code/src/... 403 # /aiseo/setup-env.php 200 /aiseo/config/paths.php 403 # /aiseo/migrate-web.php 200 # /aiseo/preflight.php 200 /aiseo/var/logs/app.log 403 # ============================================================================= RewriteEngine On # ---- blocks, before the front-controller rewrite ----------------------- # This ordering matters. If the catch-all ran first it would hand a source # path to index.php, which answers 200 — making an exposure look fine. RewriteRule ^\. - [F,L] RewriteRule ^bootstrap\.php$ - [F,L] RewriteRule ^composer\.(json|lock)$ - [F,L] RewriteRule ^(src|templates|config|bin|db|tests|var|storage|render-service|deploy|node_modules|vendor)(/|$) - [F,L] # Numbered folders are private by default, so a new 4-something/ you add # later is not public by accident. Asset paths are excluded. RewriteCond %{REQUEST_URI} !/assets/ RewriteRule ^[0-9]+-[A-Za-z0-9_-]+(/|$) - [F,L] # ---- the three temporary setup tools ----------------------------------- # setup-env.php, migrate-web.php and preflight.php. They must stay reachable # or they cannot do their job. DELETE all three once the app runs; that is the # protection, not a rule that also locks you out. RewriteRule ^(setup-env|preflight|migrate-web)\.php$ - [L] # ---- front controller --------------------------------------------------- # Real files and directories (CSS, JS, images) are served untouched. RewriteCond %{REQUEST_FILENAME} -f [OR] RewriteCond %{REQUEST_FILENAME} -d RewriteRule ^ - [L] RewriteRule ^ index.php [L] # Belt and braces for hosts without mod_rewrite. Require all denied Order allow,deny Deny from all Header always set X-Content-Type-Options "nosniff" Header always set Referrer-Policy "strict-origin-when-cross-origin" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Robots-Tag "noindex, nofollow, noarchive" ExpiresActive On ExpiresByType text/css "access plus 1 year" ExpiresByType application/javascript "access plus 1 year" # If your host answers 500 to this line, AllowOverride does not include Options. # Delete just this line. Options -Indexes