# Timber — Apache / LiteSpeed rules. (nginx ignores this file: use _dev/nginx.conf.example.)
Options -Indexes
DirectoryIndex index.php index.html

<IfModule mod_rewrite.c>
RewriteEngine On

# Never serve internals: the JSON database, PHP includes, templates, theme code, docs/dev folders (_…), dotfiles.
RewriteRule ^(data|inc|templates|themes)(/|$) - [F,L]
RewriteRule ^_ - [F,L]
RewriteRule ^@ - [F,L]
RewriteRule (^|/)\.(?!well-known/) - [F,L]
RewriteRule ^[^/]+\.(md|conf|example|json|lock)$ - [F,L]

# Only the two front controllers run PHP; uploads/ and assets/ never execute code.
RewriteRule ^(?!index\.php$)[^/]+\.php$ - [F,L]
RewriteRule ^padmin/(?!assets/)(?!index\.php$).*\.php$ - [F,L]
RewriteRule ^(uploads|assets|docs)/.*\.(php\d?|phtml|phar|pl|py|cgi|sh)$ - [F,L]

# Real files (images, css, js, a generated sitemap.xml …) are served as they are.
RewriteCond %{REQUEST_FILENAME} -f
RewriteRule ^ - [L]

# A folder with its own index.html (the /docs/ site) is served as-is.
RewriteCond %{REQUEST_FILENAME} -d
RewriteCond %{REQUEST_FILENAME}/index.html -f
RewriteRule ^ - [L]

# The admin and everything else go through a front controller.
RewriteRule ^padmin(/.*)?$ padmin/index.php [L]
RewriteRule ^ index.php [L]
</IfModule>

<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
<FilesMatch "\.(css|js|svg|png|jpe?g|gif|webp|avif|ico|woff2?|ttf|mp4|webm)$">
    Header set Cache-Control "public, max-age=31536000"
</FilesMatch>
</IfModule>

<IfModule mod_deflate.c>
AddOutputFilterByType DEFLATE text/html text/css text/plain text/xml application/javascript application/json application/xml application/rss+xml image/svg+xml
</IfModule>

<IfModule mod_php.c>
php_value upload_max_filesize 64M
php_value post_max_size 64M
</IfModule>
