# Snako - DATABASE BACKUPS. Deny all web access. (2026-08-16)
#
# WHY THIS FILE EXISTS:
# One .sql.gz in here is the ENTIRE database - customer names, phone numbers, delivery
# addresses, full order history and password hashes. It is the single worst file that
# could ever leak from this project.
#
# The parent backEnd/.htaccess already blocks db/ via mod_rewrite. This file is a SECOND,
# independent line: if mod_rewrite is off, or the parent file gets overwritten (which
# happened on 2026-08-16 - the wrong .htaccess was uploaded to the document root and took
# the whole API down), this one still denies everything on its own.
#
# ⭐ BETTER STILL: move backups OUTSIDE the document root. BACKUP_DIR is overridable -
#    define("BACKUP_DIR", "/home/<user>/snako-backups"); in config/local.php
#    Then the web server has no path to them at all, whatever happens to .htaccess.
#
# ASCII ONLY on purpose: a mojibake .htaccess is a broken .htaccess.

# Apache 2.4
<IfModule mod_authz_core.c>
  Require all denied
</IfModule>

# Apache 2.2 fallback
<IfModule !mod_authz_core.c>
  Order allow,deny
  Deny from all
</IfModule>

# Never serve these, whatever the server thinks their type is.
<FilesMatch "\.(gz|sql|sql\.gz|zip|bak)$">
  <IfModule mod_authz_core.c>
    Require all denied
  </IfModule>
  <IfModule !mod_authz_core.c>
    Order allow,deny
    Deny from all
  </IfModule>
</FilesMatch>

# No directory listing, ever.
Options -Indexes

# Belt and braces: never execute anything in here.
#
# !! MUST STAY WRAPPED IN <IfModule> !!
# A bare php_flag is a FATAL config error where PHP runs as FPM/CGI (most cPanel hosts)
# and returns HTTP 500 for the whole directory - that exact bug hit uploads/ on 2026-08-16.
<IfModule mod_php.c>
  php_flag engine off
</IfModule>
<IfModule mod_php7.c>
  php_flag engine off
</IfModule>
<IfModule mod_php5.c>
  php_flag engine off
</IfModule>

RemoveHandler .php .phtml .php3 .php4 .php5 .php7 .phar
RemoveType .php .phtml .php3 .php4 .php5 .php7 .phar
