# LSC Courier — Root .htaccess
Options -Indexes
ServerSignature Off

# Block direct access to sensitive dirs
<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteRule ^config/ - [F,L]
  RewriteRule ^core/   - [F,L]
</IfModule>

# Security headers
<IfModule mod_headers.c>
  Header always set X-Content-Type-Options "nosniff"
  Header always set X-Frame-Options "SAMEORIGIN"
  Header always set X-XSS-Protection "1; mode=block"
  Header always set Referrer-Policy "strict-origin-when-cross-origin"
</IfModule>
