# Namecheap cPanel — Node.js Selector + Passenger shared host configuration
# Place this file at: public_html/.htaccess
#
# Usage (choose one cPanel Node app pattern):
#   1) App mode root domain   -> app start file server.cjs, Application URL /
#   2) App mode subdomain     -> bot.asmonix.com DocumentRoot points to this same folder
#
# If cPanel Node.js Selector auto-generates your .htaccess, PASTE ONLY the
# SecurityHeaders + CustomErrorDocs blocks BELOW it. Do not erase Passenger lines.

<IfModule mod_headers.c>
  # --- Security headers -------------------------------------------
  Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
  Header always set X-Content-Type-Options "nosniff"
  Header always set X-Frame-Options "DENY"
  Header always set Referrer-Policy "same-origin"
  Header always set Permissions-Policy "geolocation=(), microphone=(), camera=(), payment=(), usb=(), bluetooth=()"
  Header always set X-Permitted-Cross-Domain-Policies "none"
  Header always set Expect-CT "max-age=0"
  Header unset X-Powered-By

  <FilesMatch "\.(db|sqlite|env|tpl|log)$">
    Require all denied
  </FilesMatch>
  <Files ".env">
    Require all denied
  </Files>
  <DirectoryMatch "^/(data|scripts|node_modules)/">
    Require all denied
  </DirectoryMatch>
</IfModule>

# --- Disable static serving of sensitive bot project sources ----
RedirectMatch 404 ^/data/.*
RedirectMatch 404 ^/scripts/.*
RedirectMatch 404 ^/server/.*
RedirectMatch 404 ^/bot\.txt$
RedirectMatch 404 ^/bot3\.txt$
RedirectMatch 404 ^/README_DEPLOY\.md$
RedirectMatch 404 ^/package(-lock)?\.json$

# --- Optional Custom 401 message for direct old bot.js access ---
ErrorDocument 401 /loader.js
