# Deployed into the docroot on every deploy (see bin/deploy.sh) - the
# reverse proxy to the Next.js app is configured at the vhost level, not
# here, so this file's only job is to stop LiteSpeed from serving files
# straight off disk before a request ever reaches the proxy. Without this,
# a direct request for /.env (which lives right next to the rest of the
# app in this same directory) gets served as a plain static file with all
# the app's secrets in it.
<FilesMatch "^\.">
    Require all denied
</FilesMatch>

# LiteSpeed's own page cache (LSCache) sits in front of the Node proxy and
# was observed caching full HTML responses regardless of the app's own
# Cache-Control: no-store header - after a rebuild, LSCache kept serving a
# pre-rebuild page whose script tags referenced chunk files the new build
# had already replaced, causing ChunkLoadError in the browser even though
# the running app itself was fully up to date. Every page here is either
# per-franchisee dynamic content or references build-hash-named assets
# that rotate on every deploy, so this response should never be page
# cached at all.
<IfModule LiteSpeed>
    CacheLookup off
</IfModule>

# Fallback for older Apache/LiteSpeed builds without mod_authz_core.
<IfModule !mod_authz_core.c>
    <FilesMatch "^\.">
        Order allow,deny
        Deny from all
    </FilesMatch>
</IfModule>
