# Used ONLY when the domain's document root is the application folder (typical shared hosting).
# Best practice is to point the domain at the "public" folder instead; then this file is not needed.
<IfModule mod_rewrite.c>
    RewriteEngine On
    # Never serve dotfiles (.env, .git) or internals directly
    RewriteRule (^|/)\.(?!well-known) - [F,L]
    RewriteRule ^(app|bootstrap|config|database|routes|storage|vendor|tests|resources)(/|$) - [F,L]
    RewriteRule ^$ public/ [L]
    RewriteRule (.*) public/$1 [L]
</IfModule>
<IfModule !mod_rewrite.c>
    # Without rewriting the app cannot run safely from the root: deny everything.
    Require all denied
</IfModule>
Options -Indexes
