# ── Pass Authorization header to PHP (Apache strips it by default) ──
RewriteEngine On
RewriteCond %{HTTP:Authorization} .+
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
# ── Fallback for CGI/FastCGI mode ──
SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1
# ── Deny access to sensitive files ──
Require all denied
Require all denied
Require all denied
# ── Deny access to sensitive directories ──
RewriteRule ^prevents/ - [F,L]
RewriteRule ^storage/ - [F,L]
RewriteRule ^uploads/ - [F,L]
Options -Indexes