# ============================================================
# .htaccess — Sistem Pemantauan Portal MITI (backend/public)
# Web root = direktori ini. Semua fail lain (app, config, .env,
# vendor, cli, cron) berada DI ATAS web root -> tidak diakses web.
# ============================================================

# --- Keselamatan asas ---
Options -Indexes
ServerSignature Off

# --- Lindungi fail sensitif dari akses web ---
<FilesMatch "^\.(env|htaccess|htpasswd|ini|log|sh|sql)$">
    Require all denied
</FilesMatch>

<FilesMatch "\.(php|phar)$">
    # Benarkan hanya fail PHP awam (semua dalam public adalah awam).
</FilesMatch>

# --- Had saiz upload / masa (jaga) ---
<IfModule mod_php.c>
    php_value upload_max_filesize 8M
    php_value post_max_size 8M
</IfModule>

# --- Charset ---
AddDefaultCharset UTF-8

# --- Caching statik (CSS/JS/img) untuk prestasi ---
<IfModule mod_expires.c>
    ExpiresActive On
    ExpiresByType text/css "access plus 1 week"
    ExpiresByType application/javascript "access plus 1 week"
    ExpiresByType image/png "access plus 1 month"
    ExpiresByType image/jpeg "access plus 1 month"
    ExpiresByType image/svg+xml "access plus 1 month"
</IfModule>

# --- Permudah URL (jika mahu dashboard sebagai root) ---
# Dok ini memaparkan senarai halaman; nyahahsulit jika mahu redirect root ke dashboard.
# DirectoryIndex index.php login.php dashboard.php