# Deny access to sensitive files
<Files "config.php">
Order Allow,Deny
Deny from all
</Files>
<Files "secret.key">
Order Allow,Deny
Deny from all
</Files>
<Files "*.db">
Order Allow,Deny
Deny from all
</Files>
# Security headers
Header always set X-Frame-Options "DENY"
Header always set X-Content-Type-Options "nosniff"
Header always set X-XSS-Protection "1; mode=block"
Header always set Referrer-Policy "no-referrer"
Header always set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'"
# Disable server signature
ServerTokens Prod
|