# Root .htaccess — only used when the domain's document root is the PROJECT folder
# (typical shared hosting where the docroot can't be pointed at public/).
# When the document root is public/ (recommended) every rule below is skipped.
# Uses rewrite directives only, so it works under restrictive AllowOverride settings.

<IfModule mod_rewrite.c>
    RewriteEngine On

    # Project-root mode only: skip everything if the docroot is already public/.
    RewriteCond %{DOCUMENT_ROOT} !/public/?$

    # Never serve application code, config, data or dotfiles.
    RewriteRule ^(app|config|database|storage|vendor|cron|routes|resources|tests|docs)(/|$) - [F,L,NC]

    RewriteCond %{DOCUMENT_ROOT} !/public/?$
    RewriteRule (^|/)\.(?!well-known/) - [F,L]

    RewriteCond %{DOCUMENT_ROOT} !/public/?$
    RewriteRule \.(env|sql|md|lock|log|sh|json|dist|example)$ - [F,L,NC]

    RewriteCond %{DOCUMENT_ROOT} !/public/?$
    RewriteRule ^(install\.sh|composer\.(json|lock))$ - [F,L,NC]

    # Serve everything else from public/ (URLs like /login and /admin stay unchanged).
    RewriteCond %{DOCUMENT_ROOT} !/public/?$
    RewriteCond %{REQUEST_URI} !^/public/
    RewriteCond %{REQUEST_URI} !^/\.well-known/
    RewriteRule ^(.*)$ public/$1 [L]
</IfModule>
