# EMMTECH — basic Apache hardening for shared hosting.
# (No effect on nginx; see README for nginx-equivalent rules.)

# Block direct access to sensitive files.
<FilesMatch "^(config\.php|database\.sql)$">
    Require all denied
</FilesMatch>

# Disable directory browsing.
Options -Indexes

# Force HTTPS if available (uncomment once SSL is confirmed working).
# RewriteEngine On
# RewriteCond %{HTTPS} off
# RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
