# 100300 CMS (NewCMS) — for hosting where the domain points at THIS folder
# instead of public/. If your panel lets you set the site root to public/, do
# that instead: this file is then never read.
#
# Every request is handed to public/, exactly as if public/ were the site
# root. Nothing outside public/ — config/, core/, modules/, storage/, vendor/,
# bin/, themes/, admin/ — is ever served directly: a request for
# /config/config.php becomes public/config/config.php, which does not exist,
# and the CMS answers 404. Theme, module and admin assets and uploads are
# served by the CMS itself, so they keep working. See doc/install.md.

<IfModule mod_rewrite.c>
    RewriteEngine On

    # Hosts that follow symlinks only by owner need this to rewrite at all;
    # harmless elsewhere.
    # Options +SymLinksIfOwnerMatch

    RewriteRule ^(.*)$ public/$1 [L]
</IfModule>

# No mod_rewrite: only the root index.php (which includes public/index.php)
# can answer, and the project folders must still be unreachable.
<IfModule !mod_rewrite.c>
    <IfModule mod_alias.c>
        RedirectMatch 404 (?i)/(config|core|modules|storage|vendor|bin|themes|admin|src|tests|doc|tools|dist)(/|$)
    </IfModule>
</IfModule>

# Never serve dotfiles, backups, dumps or build metadata from any folder.
<FilesMatch "^\.|\.(bak|dist|log|sql|lock|neon|ya?ml|phtml|md|py|sh)$|^composer\.(json|lock)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>
