# ============================================================================
# EXAM PORTAL - UNIVERSAL APACHE & LITESPEED CONFIGURATION
# Optimized for Hostinger (hPanel), cPanel, Nginx Reverse Proxy & Cloudflare
# ============================================================================

# 1. Directory Index - Prevents 403 Forbidden when accessing root or folders
DirectoryIndex index.php index.html index.htm

# 2. Grant Access Permissions (Apache 2.4 & Apache 2.2 compatible)
<IfModule mod_authz_core.c>
    Require all granted
</IfModule>
<IfModule !mod_authz_core.c>
    Order allow,deny
    Allow from all
</IfModule>

# 3. Disable Directory Browsing safely (stops file listing, but allows index.php)
<IfModule mod_autoindex.c>
    Options -Indexes
</IfModule>

# 4. FollowSymLinks for RewriteEngine (required by Apache mod_rewrite)
<IfModule mod_rewrite.c>
    Options +FollowSymLinks
    RewriteEngine On
    RewriteBase /

    # Map WordPress API route directly to native standalone REST API
    RewriteRule ^wp-json/examportal/v1/(.*)$ api/index.php?endpoint=$1 [QSA,L]
    RewriteRule ^wp-json/examportal/v1/?$ api/index.php?endpoint=config [QSA,L]

    # Map /api/... directly to API router
    RewriteRule ^api/(.*)$ api/index.php?endpoint=$1 [QSA,L]

    # Serve existing files and directories directly
    RewriteCond %{REQUEST_FILENAME} -f [OR]
    RewriteCond %{REQUEST_FILENAME} -d
    RewriteRule ^ - [L]

    # Fallback to index.php for front controller routing
    RewriteRule ^(.*)$ index.php [QSA,L]
</IfModule>

# 5. Cross-Origin Resource Sharing (CORS) for Mobile App & Web Clients
<IfModule mod_headers.c>
    Header always set Access-Control-Allow-Origin "*"
    Header always set Access-Control-Allow-Methods "GET, POST, PUT, DELETE, OPTIONS"
    Header always set Access-Control-Allow-Headers "Origin, X-Requested-With, Content-Type, Accept, Authorization, Referer, User-Agent"
</IfModule>

# 6. Security: Protect sensitive configuration and SQL files only
<FilesMatch "^(schema\.sql|\.git|\.env|config\.local\.php)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order allow,deny
        Deny from all
    </IfModule>
</FilesMatch>

# 7. File Upload & Execution Limits for PHP
<IfModule mod_php.c>
    php_value upload_max_filesize 64M
    php_value post_max_size 64M
    php_value max_execution_time 300
    php_value max_input_time 300
    php_value memory_limit 256M
</IfModule>
<IfModule mod_php7.c>
    php_value upload_max_filesize 64M
    php_value post_max_size 64M
    php_value max_execution_time 300
    php_value max_input_time 300
    php_value memory_limit 256M
</IfModule>
<IfModule mod_php8.c>
    php_value upload_max_filesize 64M
    php_value post_max_size 64M
    php_value max_execution_time 300
    php_value max_input_time 300
    php_value memory_limit 256M
</IfModule>
