# Apache: public/ must be the document root (or the only web-reachable folder)
Options -Indexes -MultiViews
DirectoryIndex index.php

<IfModule mod_rewrite.c>
  RewriteEngine On
  # block hidden files
  RewriteRule "(^|/)\." - [F]
</IfModule>

# PHP hardening (ignored if PHP runs as FPM — then put these in php.ini / pool config)
<IfModule mod_php.c>
  php_flag display_errors Off
  php_flag expose_php Off
  php_value session.cookie_httponly 1
</IfModule>

<FilesMatch "\.(sql|md|log|json|lock|sample|ini)$">
  Require all denied
</FilesMatch>
