# ----------------------------------------------------------------------
# Phuketer root .htaccess
# HumHub root + MediaWiki /w + Mahara /info + future WordPress /b
# ----------------------------------------------------------------------

# Correct common MIME types
AddType application/javascript .js
AddType text/css .css
AddType image/png .png
AddType image/webp .webp
AddType image/avif .avif
AddType image/svg+xml .svg
AddType font/woff2 .woff2

<IfModule mod_mime.c>
    AddType text/html .html .htm
    AddType text/css .css
    AddType text/javascript .js .mjs
    AddType application/json .json
    AddType image/svg+xml .svg
</IfModule>

# ----------------------------------------------------------------------
# Basic hardening
# ----------------------------------------------------------------------

Options -Indexes +SymLinksIfOwnerMatch

ServerSignature Off

# Block sensitive files anywhere below this root
<FilesMatch "(^\.|composer\.(json|lock|phar)$|package(-lock)?\.json$|yarn\.lock$|\.env$|LocalSettings\.php$|yii$)">
    <IfModule authz_core_module>
        Require all denied
    </IfModule>
    <IfModule !authz_core_module>
        Order deny,allow
        Deny from all
    </IfModule>
</FilesMatch>

# ----------------------------------------------------------------------
# Security headers
# ----------------------------------------------------------------------

<IfModule mod_headers.c>
    #Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=()"

    # Enable only after confirming all domains/subdomains use HTTPS correctly.
    # Start without includeSubDomains to avoid breaking future subdomains.
    Header always set Strict-Transport-Security "max-age=31536000" env=HTTPS

    # Do NOT add a strict CSP here yet.
    # HumHub + MediaWiki + Keycloak + ads + inline scripts need a tested CSP first.

	# MediaWiki MontepediaTimeless skin assets
    SetEnvIf Request_URI "^/w/skins/MontepediaTimeless/resources/.*\.(css|js|png|jpe?g|gif|webp|avif|svg|woff2?)$" SCHOOL_MW_SKIN_ASSET=1
    Header set Cache-Control "public, max-age=2592000" env=SCHOOL_MW_SKIN_ASSET
    
    # ----------------------------------------------------------------------
	# Header Permissions for Jitsi Communication
	# ----------------------------------------------------------------------

	Header set Permissions-Policy \
  		"camera=(self https://meet.jit.si https://kmeet.infomaniak.com \
  		https://jitsi.hamburg.ccc.de https://8x8.vc),\
  		microphone=(self https://meet.jit.si https://kmeet.infomaniak.com \
  		https://jitsi.hamburg.ccc.de https://8x8.vc),\
  		display-capture=(self https://meet.jit.si https://kmeet.infomaniak.com \
  		https://jitsi.hamburg.ccc.de https://8x8.vc)"
   
    # Generated/versioned HumHub assets can be cached very long
    SetEnvIf Request_URI "^/(assets|static)/" SCHOOL_VERSIONED_ASSET=1
    Header set Cache-Control "public, max-age=31536000, immutable" env=SCHOOL_VERSIONED_ASSET

    # Ads images can cache, but not too long because campaigns may change
    SetEnvIf Request_URI "^/ads/.*\.(png|jpe?g|gif|webp|avif|svg)$" SCHOOL_AD_IMAGE=1
    Header set Cache-Control "public, max-age=86400" env=SCHOOL_AD_IMAGE

    # Ads JSON should update quickly
    SetEnvIf Request_URI "^/ads/.*\.json$" SCHOOL_AD_JSON=1
    Header set Cache-Control "public, max-age=60, must-revalidate" env=SCHOOL_AD_JSON

    # Uploaded files: medium cache, not immutable
    SetEnvIf Request_URI "^/uploads/" SCHOOL_UPLOAD=1
    Header set Cache-Control "public, max-age=86400" env=SCHOOL_UPLOAD
    
</IfModule>

# ----------------------------------------------------------------------
# Compression
# ----------------------------------------------------------------------

<IfModule mod_brotli.c>
    AddOutputFilterByType BROTLI_COMPRESS text/html text/plain text/css text/xml
    AddOutputFilterByType BROTLI_COMPRESS application/javascript application/json application/xml
    AddOutputFilterByType BROTLI_COMPRESS application/rss+xml application/xhtml+xml
    AddOutputFilterByType BROTLI_COMPRESS image/svg+xml
</IfModule>

<IfModule mod_deflate.c>
    AddOutputFilterByType DEFLATE text/html text/plain text/css text/xml
    AddOutputFilterByType DEFLATE application/javascript application/json application/xml
    AddOutputFilterByType DEFLATE application/rss+xml application/xhtml+xml
    AddOutputFilterByType DEFLATE image/svg+xml
    AddOutputFilterByType DEFLATE font/ttf font/otf application/vnd.ms-fontobject
</IfModule>

# ----------------------------------------------------------------------
# Browser caching
# ----------------------------------------------------------------------

<IfModule mod_expires.c>
    ExpiresActive On

    # HTML/PHP pages should not be cached too long
    ExpiresByType text/html "access plus 0 seconds"

    # CSS / JS
    ExpiresByType text/css "access plus 30 days"
    ExpiresByType application/javascript "access plus 30 days"
    ExpiresByType text/javascript "access plus 30 days"

    # Images
    ExpiresByType image/png "access plus 30 days"
    ExpiresByType image/jpeg "access plus 30 days"
    ExpiresByType image/gif "access plus 30 days"
    ExpiresByType image/webp "access plus 30 days"
    ExpiresByType image/avif "access plus 30 days"
    ExpiresByType image/svg+xml "access plus 30 days"
    ExpiresByType image/x-icon "access plus 30 days"

    # Fonts
    ExpiresByType font/woff2 "access plus 1 year"
    ExpiresByType font/woff "access plus 1 year"
    ExpiresByType font/ttf "access plus 1 year"
    ExpiresByType font/otf "access plus 1 year"
</IfModule>

# ----------------------------------------------------------------------
# Header Permissions for Jitsi Communication
# ----------------------------------------------------------------------

Header set Permissions-Policy \
  "camera=(self https://meet.jit.si https://kmeet.infomaniak.com \
  https://jitsi.hamburg.ccc.de https://8x8.vc),\
  microphone=(self https://meet.jit.si https://kmeet.infomaniak.com \
  https://jitsi.hamburg.ccc.de https://8x8.vc),\
  display-capture=(self https://meet.jit.si https://kmeet.infomaniak.com \
  https://jitsi.hamburg.ccc.de https://8x8.vc)"
  
# ----------------------------------------------------------------------
# Rewrite routing
# ----------------------------------------------------------------------

<IfModule mod_rewrite.c>
    RewriteEngine On

    # ------------------------------------------------------------
    # 1. Let's Encrypt must never redirect
    # ------------------------------------------------------------
    RewriteRule ^\.well-known/acme-challenge/[A-Za-z0-9_-]+$ - [L]

    # ------------------------------------------------------------
    # 2. Block protected/private paths before physical-file passthrough
    # ------------------------------------------------------------
    RewriteRule ^protected(/|$) - [F,L,NC]
    RewriteRule ^vendor(/|$) - [F,L,NC]
    RewriteRule ^runtime(/|$) - [F,L,NC]
    RewriteRule ^\.git(/|$) - [F,L,NC]
    RewriteRule (^|.*/)(LocalSettings\.php|composer\.(json|lock|phar)|\.env|yii)$ - [F,L,NC]

    # ------------------------------------------------------------
    # 3. Alias / external domain redirects
    # Put these before generic HTTPS to avoid double redirects.
    # ------------------------------------------------------------

    # Redirects of Phuket.School    
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?phuket.school [NC]
		RewriteRule ^(.*)$ https://phuketer.com/cat?abc_category=91 [L,R=301,NC]
    
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?my.phuket.school [NC]
		RewriteRule ^(.*)$ https://my.phuketer.com [L,R=301,NC]
    
    # Redirects of Phuket.Church
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?phuket.church [NC]
		RewriteRule ^(.*)$ https://phuketer.com/cat?abc_category=72 [L,R=301,NC]
    
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?freedom.phuket.church [NC]
		RewriteRule ^(.*)$ https://phuketer.com/s/freedom/ [L,R=301,NC]
    
    # Redirects of FlyingPhuket.Com    
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?flyingphuket.com [NC]
		RewriteRule ^(.*)$ https://phuketer.com/cat?abc_category=88 [L,R=301,NC]
    
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?friends.flyingphuket.com [NC]
		RewriteRule ^(.*)$ https://phuketer.com/s/phuket-flying-club/ [L,R=301,NC]
    
    # Redirects of RecyclePhuket.com
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?recyclephuket.com [NC]
		RewriteRule ^(.*)$ https://phuketer.com/cat?abc_category=97 [L,R=301,NC]

	# Redirects of PhuketProms.Com
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?phuketproms.com [NC]
		RewriteRule ^(.*)$ https://phuketer.com/cat?abc_category=129 [L,R=301,NC]

	# Redirects of Educationvisaphuket.com
    	RewriteCond %{HTTP_HOST} ^(?:www\.)?educationvisaphuket.com [NC]
		RewriteRule ^(.*)$ https://phuketer.com/s/00000230/ [L,R=301,NC]

    # ------------------------------------------------------------
    # 4. Force HTTPS for normal requests, but never for Let's Encrypt
    # ------------------------------------------------------------
    RewriteCond %{HTTPS} !=on
	RewriteCond %{REMOTE_ADDR} !^127\.0\.0\.1$
	RewriteCond %{REQUEST_URI} !^/\.well-known/acme-challenge/[A-Za-z0-9_-]+$ [NC]
	RewriteRule ^(.*)$ https://phuketer.com/$1 [R=301,L,NE]

    # ------------------------------------------------------------
    # 5. Root landing page
    # Current HumHub mobile/app landing:
    # ------------------------------------------------------------
    # Montepedia public start page: serve MediaWiki Main Page internally
	#RewriteRule ^$ /w/index.php?title=Main_Page [L,QSA]
	
    # ------------------------------------------------------------
    # 6. MediaWiki virtual article path
    # /wiki/Main_Page -> /w/index.php
    # ------------------------------------------------------------
    RewriteRule ^wiki/?(.*)$ /w/index.php [L,QSA]

    # ------------------------------------------------------------
    # 7. Keep standalone applications out of HumHub catch-all
    # ------------------------------------------------------------
    RewriteRule ^(?:w|info|b|j|m|yii3-dev)(/|$) - [L,NC]

    # ------------------------------------------------------------
    # 8. HumHub permalink compatibility
    # ------------------------------------------------------------
    RewriteCond %{QUERY_STRING} ^r=content(/|%2)perma&id=([0-9]*)$
    RewriteRule ^index\.php$ %{REQUEST_URI}/content/perma/?id=%2 [R=302,L]

    # ------------------------------------------------------------
    # 9. Base path detection for HumHub
    # ------------------------------------------------------------
    RewriteCond %{REQUEST_URI}::$1 ^(/.+)/(.*)::\2$
    RewriteRule ^(.*)$ - [E=BASE:%1]

    # ------------------------------------------------------------
    # 10. Preserve Authorization header for APIs / mobile / SSO
    # ------------------------------------------------------------
    RewriteCond %{HTTP:Authorization} .
    RewriteRule ^ - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

    # ------------------------------------------------------------
    # 11. Let real files and directories pass through
    # This is important for /assets, /static, /uploads, /ads, /w, /info, /b
    # ------------------------------------------------------------
    RewriteCond %{REQUEST_FILENAME} -f [OR]
    RewriteCond %{REQUEST_FILENAME} -d
    RewriteRule ^ - [L]
    
    # 2. Let T3/ABC3 runtime handle its own requests
		RewriteCond %{REQUEST_URI} ^/abc3(?:/|$) [NC]
		RewriteRule ^ - [L]

	# 3. Let yii3-dev handle its own requests
		RewriteCond %{REQUEST_URI} ^/yii3-dev(?:/|$) [NC]
		RewriteRule ^ - [L]

    # ------------------------------------------------------------
    # 12. HumHub final catch-all
    # ------------------------------------------------------------
    RewriteRule ^ %{ENV:BASE}/index.php [L]

	# ------------------------------------------------------------
    # 13. Prevent HumHub from processing /directory files
    # ------------------------------------------------------------
    RewriteRule ^directory(?:/|$) - [L]

</IfModule>