Require all granted
Options -Indexes -MultiViews
DirectoryIndex index.html

# Batas ukuran permintaan (foto maksimal 4 MB + sedikit ruang untuk kolom formulir)
LimitRequestBody 6291456

# ---------------------------------------------------------------- Header keamanan
<IfModule mod_headers.c>
  Header always set X-Content-Type-Options "nosniff"
  Header always set X-Frame-Options "DENY"
  Header always set Referrer-Policy "strict-origin-when-cross-origin"
  Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()"
  Header always set Cross-Origin-Opener-Policy "same-origin"
  Header always set Cross-Origin-Resource-Policy "same-origin"
  # Vue versi CDN mengompilasi templat di browser sehingga butuh 'unsafe-eval'. Skrip dari luar & inline tetap diblokir.
  Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-eval'; style-src 'self' https://fonts.googleapis.com; font-src https://fonts.gstatic.com; img-src 'self' data:; connect-src 'self'; manifest-src 'self'; worker-src 'self'; object-src 'none'; base-uri 'none'; form-action 'self'; frame-ancestors 'none'"
  Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" "expr=%{HTTPS} == 'on'"
  Header always unset X-Powered-By
</IfModule>

# ---------------------------------------------------------------- Berkas yang tidak boleh diakses lewat web
<FilesMatch "(^\.|\.(sql|md|bak|old|orig|swp|log|ini|sh|inc|lock|env|json\.bak)$|~$)">
  Require all denied
</FilesMatch>
<FilesMatch "^\.well-known$">
  Require all granted
</FilesMatch>

# ---------------------------------------------------------------- PWA
AddType application/manifest+json .webmanifest
<Files "sw.js">
  <IfModule mod_headers.c>
    Header set Cache-Control "no-cache"
  </IfModule>
</Files>

# Sembunyikan versi PHP (bila PHP berjalan sebagai modul Apache)
<IfModule mod_php.c>
  php_flag expose_php off
  php_flag display_errors off
</IfModule>
