# ISP IRP System - .htaccess (opsional, untuk Apache)
# Aktifkan jika ingin pretty URL / security headers

Options -Indexes
DirectoryIndex index.php login.php

<IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    # Tidak ada pretty URL kompleks agar PHP murni tetap sederhana
</IfModule>

# Security headers
<IfModule mod_headers.c>
    Header set X-Content-Type-Options "nosniff"
    Header set X-Frame-Options "SAMEORIGIN"
    Header set X-XSS-Protection "1; mode=block"
</IfModule>

# Mencegah akses langsung ke file sensitif
<FilesMatch "^(config|includes)/.*\.php$">
    # allow include via PHP, but block direct access (kalau perlu)
</FilesMatch>

# Prevent directory listing of uploads
<IfModule mod_autoindex.c>
    Options -Indexes
</IfModule>
