# Security hardening: this directory only ever holds uploaded documents/
# images (product datasheets, and from Phase 6 onward, chat attachments).
# Nothing in here should ever be executed as a script, even if someone
# manages to upload a file with a misleading extension.

# Apache 2.4+
<IfModule mod_authz_core.c>
    <FilesMatch "\.(php|php\d?|phtml|pl|py|cgi|sh|asp|aspx)$">
        Require all denied
    </FilesMatch>
</IfModule>

# Apache 2.2 fallback
<IfModule !mod_authz_core.c>
    <FilesMatch "\.(php|php\d?|phtml|pl|py|cgi|sh|asp|aspx)$">
        Order allow,deny
        Deny from all
    </FilesMatch>
</IfModule>

# Belt-and-braces: even if the above module checks don't apply on this
# host, disabling the PHP handler for this directory stops PHP execution.
<IfModule mod_php7.c>
    php_flag engine off
</IfModule>
<IfModule mod_php8.c>
    php_flag engine off
</IfModule>

Options -ExecCGI
AddHandler cgi-script .php .phtml .pl .py .cgi .sh
