# 1. Disable Directory Browsing (Prevents hackers from seeing your files)
Options -Indexes

# 2. Block Direct File Access to Core Folders
# Forces ALL traffic to go through index.php. If they try to hit a module directly, they get a 403 Forbidden error.
RewriteEngine On
RewriteRule ^(modules|includes|config|vendor)/ - [F,L]

# 3. Block Access to Sensitive System Files
<FilesMatch "^\.|\.(ini|log|sh|env|md)$">
    Require all denied
</FilesMatch>

# 4. Prevent Clickjacking (X-Frame-Options)
Header always append X-Frame-Options SAMEORIGIN

# 5. Enforce HTTPS (Uncomment the two lines below when you upload to the live web server)
# RewriteCond %{HTTPS} off
# RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]