# ── Pass Authorization header to PHP (Apache strips it by default) ── RewriteEngine On RewriteCond %{HTTP:Authorization} .+ RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] # ── Fallback for CGI/FastCGI mode ── SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1 # ── Deny access to sensitive files ── Require all denied Require all denied Require all denied # ── Deny access to sensitive directories ── RewriteRule ^prevents/ - [F,L] RewriteRule ^storage/ - [F,L] RewriteRule ^uploads/ - [F,L] Options -Indexes