| | |
| | | # security rules: |
| | | # - deny access to files not containing a dot or starting with a dot |
| | | # in all locations except installer directory |
| | | RewriteRule ^(?!installer|[a-f0-9]{16})(\.?[^\.]+)$ - [F] |
| | | RewriteRule ^(?!installer|\.well-known\/|[a-zA-Z0-9]{16})(\.?[^\.]+)$ - [F] |
| | | # - deny access to some locations |
| | | RewriteRule ^/?(\.git|\.tx|SQL|bin|config|logs|temp|tests|program\/(include|lib|localization|steps)) - [F] |
| | | # - deny access to some documentation files |
| | |
| | | <IfModule mod_headers.c> |
| | | # replace 'append' with 'merge' for Apache version 2.2.9 and later |
| | | #Header append Cache-Control public env=!NO_CACHE |
| | | # for better privacy/security ask browsers to not set the Referer |
| | | #Header set Content-Security-Policy "referrer no-referrer" |
| | | </IfModule> |
| | | |
| | | <IfModule mod_expires.c> |