# Used only when the website's document root is this folder (e.g. the app was
# extracted straight into public_html). Everything is served from public/, so
# .env, storage, vendor and the source code can never be downloaded.
# Better, when cPanel allows it: point the domain's document root at public/.

<IfModule mod_rewrite.c>
    RewriteEngine On

    # Pass the Authorization header through (analyzer API keys).
    RewriteCond %{HTTP:Authorization} .
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

    # Remove a trailing slash here, so the redirect does not expose /public/.
    RewriteCond %{REQUEST_URI} (.+)/$
    RewriteRule ^ %1 [L,R=301]

    RewriteRule ^(.*)$ public/$1 [L]
</IfModule>

# Without mod_rewrite, refuse everything rather than expose files.
<IfModule !mod_rewrite.c>
    Require all denied
</IfModule>

# Never serve dotfiles (.env, .git …) even if a rule above is changed.
<FilesMatch "^\.">
    Require all denied
</FilesMatch>
Options -Indexes
