# Drop-in routing for cPanel. Works on ANY domain with no editing.
#
# Best:      point the domain's "Document Root" at the  public  folder (cPanel > Domains). Then this file is never used.
# Also fine: leave the Document Root on THIS folder. The rules below quietly send every request into public/ and
#            nothing outside public/ can ever be fetched (app code, .env, migrations, storage, backups...).
Options -Indexes
<IfModule mod_rewrite.c>
    RewriteEngine On
    # Let cPanel AutoSSL / Let's Encrypt renew the certificate (it writes files under /.well-known/ in this folder)
    RewriteCond %{REQUEST_URI} !^/.well-known/
    RewriteCond %{REQUEST_URI} !^/public/
    RewriteRule ^(.*)$ public/$1 [L]
</IfModule>
# If mod_rewrite is missing, refuse everything rather than expose the project folder.
<IfModule !mod_rewrite.c>
    Require all denied
</IfModule>
<FilesMatch "^\.|\.(sql|md|key|bat|ps1|zip|log|env)$">
    Require all denied
</FilesMatch>
