# MaziwaPlus Portal - basic hardening for shared hosting

# Never allow the schema file to be downloaded directly
<FilesMatch "\.(sql|md)$">
    Require all denied
</FilesMatch>

Options -Indexes

# Sensible PHP defaults if allowed by the host (harmless if not permitted)
<IfModule mod_php.c>
    php_flag display_errors off
    php_value upload_max_filesize 10M
    php_value post_max_size 10M
</IfModule>

# Security headers. CSP allows the two CDNs the app actually loads
# (jsdelivr for Bootstrap/Chart.js, Google Fonts) and 'unsafe-inline' for
# script/style, since the app relies on inline <script> blocks and
# onclick/onsubmit attributes throughout rather than a nonce-based build
# step - this still blocks arbitrary remote script/object/frame sources
# and cross-origin framing, which is the bulk of the real-world benefit.
<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
    Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net; style-src 'self' 'unsafe-inline' https://cdn.jsdelivr.net https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self'; object-src 'none'; base-uri 'self'; frame-ancestors 'self'"
</IfModule>
