# ISP Billing Cloud — web server rules

# Block direct access to sensitive files
<FilesMatch "^(config\.php|.*\.sql|install\.done\.php|upgrade\.done\.php)$">
    Require all denied
</FilesMatch>

# Cache policy: index.html must ALWAYS be fresh — it carries the ?v=NN asset
# versions, so a stale HTML defeats cache-busting. (The server page-cache was
# serving 15-day-old HTML, hiding new releases from phones.)
<IfModule mod_headers.c>
    <FilesMatch "^index\.html$">
        Header set Cache-Control "no-store, no-cache, must-revalidate, max-age=0"
        Header set CDN-Cache-Control "no-store"
        Header unset Expires
    </FilesMatch>
</IfModule>

# Make the Authorization header reach PHP (some shared hosts strip it,
# which would break API login). Harmless when the header already passes through.
<IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
</IfModule>

# Force HTTPS (uncomment after SSL is active on your subdomain)
# <IfModule mod_rewrite.c>
#     RewriteEngine On
#     RewriteCond %{HTTPS} off
#     RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
# </IfModule>
