DirectorySlash Off # Block direct access to content source files # Allow only the entry point, and the standalone /publiser admin app Require all denied # Security headers Header set X-Content-Type-Options "nosniff" Header set X-Frame-Options "DENY" Header set Referrer-Policy "strict-origin-when-cross-origin" Header set Permissions-Policy "camera=(), microphone=(), geolocation=()" Header unset X-Powered-By Header always unset X-Powered-By # Restrict HTTP methods to GET, POST, HEAD RewriteEngine On RewriteBase / RewriteCond %{REQUEST_METHOD} !^(GET|POST|HEAD)$ [NC] RewriteRule .* - [F,L] # Route /app requests to index.php RewriteCond %{REQUEST_URI} ^/app/ RewriteRule ^(.*)$ /index.php [L,QSA] # Standalone /publiser admin app - bypass the CMS entirely, dispatch # everything to its own entry point (static assets like .css/.js are # excluded so Apache serves those files directly) RewriteCond %{REQUEST_URI} ^/publiser RewriteCond %{REQUEST_URI} !\.(css|js|png|jpe?g|webp|gif|svg)$ RewriteRule ^publiser(/.*)?$ publiser/index.php [L,QSA] # Don't rewrite if file exists RewriteCond %{REQUEST_FILENAME} !-f RewriteRule ^(.*)$ /index.php [L,QSA]