# Snako - logs are PRIVATE. Deny all web access.
#
# WHY (found 2026-08-13): http://<host>/backEnd/logs/error.log returned HTTP 200.
# error.log leaks stack traces, absolute server paths and SQL fragments.
# mail.log leaks CUSTOMER data: names, e-mail addresses, order contents (GDPR).
# Nothing in here is ever meant to be fetched over HTTP - the watchdogs read it
# from disk (tools/error-report.php).
#
# ASCII ONLY on purpose: a mojibake .htaccess is a broken .htaccess.

# Apache 2.4
<IfModule mod_authz_core.c>
  Require all denied
</IfModule>

# Apache 2.2 fallback
<IfModule !mod_authz_core.c>
  Order allow,deny
  Deny from all
</IfModule>

# Belt and braces: never execute anything in here either.
#
# !! MUST STAY WRAPPED IN <IfModule> !!
# 2026-08-16: the identical bare directive in uploads/.htaccess made every file under
# /uploads/ answer HTTP 500 on cPanel (PHP-FPM/LSAPI), where a bare php_flag is a FATAL
# config error. Here it only turned a clean 403 into a confusing 500, but it is the same
# bug - fixed together so the next person does not copy the broken pattern.
<IfModule mod_php.c>
  php_flag engine off
</IfModule>
<IfModule mod_php7.c>
  php_flag engine off
</IfModule>
<IfModule mod_php5.c>
  php_flag engine off
</IfModule>

RemoveHandler .php .phtml .php3 .php4 .php5 .php7 .phar
RemoveType .php .phtml .php3 .php4 .php5 .php7 .phar
