# Compliance-Cockpit: Schutz der Daten- und Programmordner, HTTPS, Upload-Grenze
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteCond %{HTTPS} !=on
  RewriteCond %{HTTP:X-Forwarded-Proto} !=https
  RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
</IfModule>

# Kein direkter Zugriff auf Datenbank, Uploads und Programmteile
RedirectMatch 404 ^/.*/(data|inc|pages)(/|$)
<FilesMatch "^(config\.php|config\.sample\.php|\.htaccess|.*\.sqlite)$">
  Require all denied
</FilesMatch>

<IfModule mod_headers.c>
  Header set X-Robots-Tag "noindex, nofollow"
  Header set X-Content-Type-Options "nosniff"
</IfModule>

<IfModule mod_php.c>
  php_value upload_max_filesize 20M
  php_value post_max_size 25M
  php_value session.cookie_httponly 1
</IfModule>
Options -Indexes
