# ========================================
# LARAVEL HARDENED SECURITY .HTACCESS
# ========================================

<IfModule mod_rewrite.c>
    Options -Indexes -MultiViews
    RewriteEngine On

    # Fix Authorization Header
    RewriteCond %{HTTP:Authorization} .
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

    # Remove trailing slash
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteCond %{REQUEST_URI} (.+)/$
    RewriteRule ^ %1 [L,R=301]

    # Laravel Front Controller
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteRule ^ index.php [L]
</IfModule>

# ====================================================
# 1) BLOCK FILE SENSITIF (ENV, JSON, TXT, LOG, DLL)
# ====================================================
<FilesMatch "\.(env|txt|log|sql|bak|ini|md|sh|config|json|yml|yaml|key)$">
    Require all denied
</FilesMatch>

# BLOCK FILE TERTENTU SECARA SPESIFIK
<Files "req.txt">
    Require all denied
</Files>

<Files ".env">
    Require all denied
</Files>

<Files "composer.json">
    Require all denied
</Files>

<Files "req.txt">
    Order Allow,Deny
    Deny from all
</Files>


# ====================================================
# 2) BLOCK AKSES KE SISTEM LARAVEL
# ====================================================
RewriteRule ^(vendor|storage|bootstrap|database|resources|tests|node_modules) - [F,L]

# ====================================================
# 3) BLOCK EXECUTION FILE PHP DI PUBLIC (ANTI-SHELL)
# ====================================================
<FilesMatch "\.(php|php3|php4|php5|php7|php8|phtml)$">
    Require all denied
</FilesMatch>

# Tetapi izinkan index.php tetap berjalan
<Files "index.php">
    Require all granted
</Files>

# ====================================================
# 4) BLOCK SCANNING BOT (dirsearch, wpscan, python-requests)
# ====================================================
SetEnvIfNoCase User-Agent "dirbuster" bad_bot
SetEnvIfNoCase User-Agent "dirb" bad_bot
SetEnvIfNoCase User-Agent "nikto" bad_bot
SetEnvIfNoCase User-Agent "sqlmap" bad_bot
SetEnvIfNoCase User-Agent "python" bad_bot
SetEnvIfNoCase User-Agent "curl" bad_bot
SetEnvIfNoCase User-Agent "wget" bad_bot

Order allow,deny
Allow from all
Deny from env=bad_bot

# ====================================================
# 5) BLOCK FILE UPLOAD BERPOTENSI WEB SHELL
# ====================================================
<FilesMatch "\.(php|php3|php4|php5|php7|php8|phtml|phar)$">
    Require all denied
</FilesMatch>

# ====================================================
# 6) ANTI HOTLINK (CEGAH AMBIL GAMBAR TANPA IZIN)
# ====================================================
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !greenerfund\.site [NC]
RewriteRule \.(jpg|jpeg|png|gif|webp)$ - [F,L]

# ====================================================
# 7) RATE LIMIT (ANTI REQUEST FLOOD)
# ====================================================
<IfModule mod_evasive20.c>
    DOSHashTableSize    3097
    DOSPageCount        5
    DOSPageInterval     1
    DOSSiteCount        50
    DOSSiteInterval     1
    DOSBlockingPeriod   60
</IfModule>

# ====================================================
# 8) MIME TYPE SAFE – CEGAH FILE UPLOAD DISAMARIN
# ====================================================
AddType text/plain .log .txt .bak .sql .ini .conf
AddType application/json .json

# ====================================================
# 9) SECURITY HEADER
# ====================================================
<IfModule mod_headers.c>
    Header always set X-Frame-Options SAMEORIGIN
    Header always set X-Content-Type-Options nosniff
    Header always set Referrer-Policy "strict-origin"
    Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()"
    Header set Access-Control-Allow-Origin "*"
</IfModule>

# ====================================================
# CPANEL HANDLER (JANGAN DIHAPUS)
# ====================================================
<IfModule mime_module>
  AddHandler application/x-httpd-ea-php80 .php .php8 .phtml
</IfModule>
