RewriteEngine On
RewriteBase /

# Protect application, system, database folders from direct browser access
RewriteCond %{REQUEST_URI} ^/(application|system|database)($|/) [NC]
RewriteRule .* - [F,L]

# Allow direct access to real files/folders (css, js, images, uploads)
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d

# Route everything else through index.php (removes index.php from URL)
RewriteRule ^(.*)$ index.php/$1 [L,QSA]

# Security headers
<IfModule mod_headers.c>
    Header set X-Content-Type-Options "nosniff"
    Header set X-Frame-Options "SAMEORIGIN"
    Header set X-XSS-Protection "1; mode=block"
    Header set Referrer-Policy "strict-origin-when-cross-origin"
</IfModule>

# Disable directory listing
Options -Indexes

<IfModule mod_php7.c>
    php_value upload_max_filesize 10M
    php_value post_max_size 12M
</IfModule>
