# If the app cannot find the lapu_app folder, uncomment and set its real path:
# SetEnv LAPU_APP_PATH /home/YOURCPANELUSER/lapu_app

Options -Indexes
DirectoryIndex index.html

<IfModule mod_rewrite.c>
  RewriteEngine On
  # some shared hosts strip the Authorization header
  RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
  RewriteRule ^(admin|login|register|panel)/?$ panel.html [L]
  RewriteCond %{REQUEST_FILENAME} !-f
  RewriteRule ^api/ api/index.php [L,QSA]
</IfModule>

<IfModule mod_headers.c>
  Header always set X-Content-Type-Options "nosniff"
  Header always set X-Frame-Options "DENY"
  Header always set Referrer-Policy "same-origin"
  Header always set Content-Security-Policy "default-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; connect-src 'self'; frame-ancestors 'none'"
</IfModule>

<FilesMatch "\.(sql|md|log|lock|sample\.php)$">
  <IfModule mod_authz_core.c>
    Require all denied
  </IfModule>
</FilesMatch>
