# Updates for the shop desktop app (electron-updater, generic provider).
# The app asks here every 30 min: latest.yml -> "snako food app Setup X.Y.Z.exe".
# test/ = test channel (one PC with "updateChannel": "test" in server.json).
#
# Static files only. No scripts may ever run from here.
# ASCII only on purpose: a mojibake .htaccess is a broken .htaccess.

<IfModule mod_php.c>
  php_flag engine off
</IfModule>
<IfModule mod_php7.c>
  php_flag engine off
</IfModule>
<IfModule mod_php5.c>
  php_flag engine off
</IfModule>

RemoveHandler .php .phtml .php3 .php4 .php5 .php7 .phar
RemoveType .php .phtml .php3 .php4 .php5 .php7 .phar
<FilesMatch "\.(php|phtml|php3|php4|php5|php7|phar|cgi|pl|py|sh)$">
  Require all denied
</FilesMatch>

Options -Indexes

AddType application/octet-stream .exe .blockmap
AddType text/yaml .yml

# latest.yml MUST never be cached: it is how a shop learns a new version exists.
# A stale copy = shops silently stuck on the old version.
# Wrapped: without mod_headers a bare Header line = HTTP 500 for the whole folder.
<IfModule mod_headers.c>
  <FilesMatch "\.yml$">
    Header set Cache-Control "no-cache, no-store, must-revalidate"
  </FilesMatch>
  Header set X-Content-Type-Options "nosniff"
</IfModule>

# The instructions file is for us, not for the internet.
<FilesMatch "\.md$">
  Require all denied
</FilesMatch>
