# Namecheap cPanel: best is Domains → document root = this project's public folder.
# If the document root stays on this folder, the rules below send visitors into public/
# and refuse direct access to the app, .env, and database.

Options -Indexes

<IfModule mod_authz_core.c>
    <FilesMatch "(^\.env|\.sqlite$|\.log$)">
        Require all denied
    </FilesMatch>
</IfModule>

<IfModule mod_rewrite.c>
    RewriteEngine On

    RewriteRule ^(?:\.env(?:\..*)?|\.git|composer\.(?:json|lock)|package(?:-lock)?\.json|vite\.config\.js|artisan)$ - [F,L]
    RewriteRule ^(?:app|bootstrap|config|database|resources|routes|storage|tests|vendor|node_modules)(?:/|$) - [F,L]

    RewriteCond %{REQUEST_URI} !/public/
    RewriteRule ^(.*)$ public/$1 [L]
</IfModule>
