<IfModule mod_rewrite.c>
    <IfModule mod_negotiation.c>
        Options -MultiViews -Indexes
    </IfModule>

    RewriteEngine On

    # Handle Authorization Header
    RewriteCond %{HTTP:Authorization} .
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

    # Handle X-XSRF-Token Header
    RewriteCond %{HTTP:x-xsrf-token} .
    RewriteRule .* - [E=HTTP_X_XSRF_TOKEN:%{HTTP:X-XSRF-Token}]

    # ── Client documents are PRIVATE (audit C-01) ─────────────────────────
    # storage/clients/** holds CNIC scans, bank statements, salary slips and
    # filed tax returns. These are served ONLY through authenticated
    # controller routes (documents.download / documents.view /
    # tax-returns.file), which check the owning client's visibility first.
    #
    # This rule is the belt to that braces: a direct request must never be
    # satisfied from disk even if a file is still physically present under
    # public/storage — which is exactly what happened on the v1.1.3 install,
    # where the relocation ran but the delete step silently failed and left
    # the originals publicly fetchable. Deny first, move second.
    RewriteRule ^storage/clients/ - [F,L]

    # Redirect Trailing Slashes If Not A Folder...
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteCond %{REQUEST_URI} (.+)/$
    RewriteRule ^ %1 [L,R=301]

    # Send Requests To Front Controller...
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteRule ^ index.php [L]
</IfModule>

# ── Security Headers ──────────────────────────────────────────────────────────
<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set X-XSS-Protection "1; mode=block"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()"
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
</IfModule>

# ── Block Sensitive Files ─────────────────────────────────────────────────────
<FilesMatch "(\.env|\.git|composer\.(json|lock)|package\.json|artisan)$">
    Order allow,deny
    Deny from all
</FilesMatch>

# ── Prevent Directory Listing ─────────────────────────────────────────────────
Options -Indexes

# ── Compression ───────────────────────────────────────────────────────────────
<IfModule mod_deflate.c>
    AddOutputFilterByType DEFLATE text/plain text/html text/xml text/css
    AddOutputFilterByType DEFLATE application/xml application/xhtml+xml
    AddOutputFilterByType DEFLATE application/javascript application/x-javascript
</IfModule>

# ── Browser Caching ───────────────────────────────────────────────────────────
# NOTE: mod_expires is NOT loaded on the production Apache, so this block is
# inert there. The mod_headers block below does the real work in production.
<IfModule mod_expires.c>
    ExpiresActive On
    ExpiresByType image/jpg "access plus 1 year"
    ExpiresByType image/jpeg "access plus 1 year"
    ExpiresByType image/gif "access plus 1 year"
    ExpiresByType image/png "access plus 1 year"
    ExpiresByType image/webp "access plus 1 year"
    ExpiresByType text/css "access plus 1 month"
    ExpiresByType application/javascript "access plus 1 month"
</IfModule>

# Vite build assets carry a content hash in the filename (e.g. app-C78hCmp2.css),
# so a changed file always gets a NEW URL — the old one can be cached forever.
# Biggest repeat-visit win: browsers & Cloudflare stop re-downloading ~500KB of
# CSS/JS/fonts on every visit (previously capped at Cloudflare's 4h default).
<IfModule mod_headers.c>
    <FilesMatch "\.(css|js|woff2?|ttf|otf|eot|svg)$">
        Header set Cache-Control "public, max-age=31536000, immutable"
    </FilesMatch>

    # The Android APK keeps ONE canonical URL (/LifeAssociate.apk) that gets
    # overwritten on every release — Cloudflare caches .apk by default, which
    # left staff downloading a stale build. no-cache forces revalidation.
    <FilesMatch "\.apk$">
        Header set Cache-Control "no-cache, must-revalidate"
    </FilesMatch>
</IfModule>
