DirectorySlash Off
# Block direct access to content source files
# Allow only the entry point, and the standalone /publiser admin app
Require all denied
# Security headers
Header set X-Content-Type-Options "nosniff"
Header set X-Frame-Options "DENY"
Header set Referrer-Policy "strict-origin-when-cross-origin"
Header set Permissions-Policy "camera=(), microphone=(), geolocation=()"
Header unset X-Powered-By
Header always unset X-Powered-By
# Restrict HTTP methods to GET, POST, HEAD
RewriteEngine On
RewriteBase /
RewriteCond %{REQUEST_METHOD} !^(GET|POST|HEAD)$ [NC]
RewriteRule .* - [F,L]
# Route /app requests to index.php
RewriteCond %{REQUEST_URI} ^/app/
RewriteRule ^(.*)$ /index.php [L,QSA]
# Standalone /publiser admin app - bypass the CMS entirely, dispatch
# everything to its own entry point (static assets like .css/.js are
# excluded so Apache serves those files directly)
RewriteCond %{REQUEST_URI} ^/publiser
RewriteCond %{REQUEST_URI} !\.(css|js|png|jpe?g|webp|gif|svg)$
RewriteRule ^publiser(/.*)?$ publiser/index.php [L,QSA]
# Don't rewrite if file exists
RewriteCond %{REQUEST_FILENAME} !-f
RewriteRule ^(.*)$ /index.php [L,QSA]