# Apache / LiteSpeed configuration for Glen Ridge Private Wealth Business Emailer on cPanel
RewriteEngine On

# 1. Protect database and internal source code from direct public browser access
<FilesMatch "\.(db|sqlite|sqlite3|py|pyc|log|md|sh|env)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order deny,allow
        Deny from all
    </IfModule>
</FilesMatch>

# 2. Block direct access to data directory
RewriteRule ^data/ - [F,L]

# 3. Allow Apache to serve static files (CSS, JS, images) directly for maximum speed
RewriteCond %{REQUEST_URI} ^/static/
RewriteCond %{REQUEST_FILENAME} -f
RewriteRule ^ - [L]

# 4. Route all other requests through Phusion Passenger / Python WSGI
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^(.*)$ passenger_wsgi.py [QSA,L]

# 5. Security Headers
<IfModule mod_headers.c>
    Header set X-Content-Type-Options "nosniff"
    Header set X-XSS-Protection "1; mode=block"
    Header set X-Frame-Options "SAMEORIGIN"
</IfModule>
