# Infumia LTD - Proje koku koruma ve cPanel yonlendirme
# En iyi kurulum: domain document root'unu /public klasorune ver.
# Eger cPanel'de proje koku web root olursa bu dosya hassas klasorleri kapatir.

Options -Indexes
AddDefaultCharset UTF-8
AddType image/x-icon .ico
AddType image/webp .webp
AddType image/avif .avif
AddType font/woff2 .woff2

<FilesMatch "^\.|(\.env|\.ini|\.log|\.sql|\.bak|\.backup|\.old|\.orig|\.save|composer\.(json|lock)|package(-lock)?\.json|yarn\.lock)$">
    Require all denied
</FilesMatch>

<IfModule mod_rewrite.c>
    RewriteEngine On

    # --- HTTPS zorunlu (SEO + güvenlik) ---
    # HTTP isteklerini HTTPS'e yönlendir. Tek domain, tek protokol = duplicate content yok.
    RewriteCond %{HTTPS} off
    RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]

    # --- www → non-www (duplicate content önlemi) ---
    # www.infumia.com ile infumia.com ayrı URL sayılır. Tek canonical domain.
    RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
    RewriteRule ^ https://%1%{REQUEST_URI} [R=301,L]

    # Hassas uygulama klasorleri asla direkt gezilmesin.
    RewriteRule ^(app|backups|config|database|resources|storage|vendor|node_modules)(/|$) - [F,L,NC]

    # Kök seviye özel dosyalar (app-ads.txt, robots.txt, sitemap.xml) — URL degismeden serve et.
    # Bu dosyalar public/ altinda, Google bunlari kok seviyesinde ister.
    RewriteRule ^app-ads\.txt$ public/app-ads.txt [L]
    RewriteRule ^robots\.txt$ public/robots.txt [L]
    RewriteRule ^sitemap\.xml$ public/sitemap.xml [L]
    RewriteRule ^ads\.txt$ public/ads.txt [L]
    # llms.txt AI arama motorları için — front controller üzerinden dinamik.
    RewriteRule ^llms\.txt$ public/index.php [L]

    # Public icindeki gercek dosya/klasorleri servis et.
    RewriteCond %{DOCUMENT_ROOT}/public%{REQUEST_URI} -f [OR]
    RewriteCond %{DOCUMENT_ROOT}/public%{REQUEST_URI} -d
    RewriteRule ^(.*)$ public/$1 [L]

    # Geri kalan istekler front controller'a.
    RewriteRule ^ public/index.php [QSA,L]
</IfModule>

<IfModule mod_headers.c>
    <FilesMatch "\.(css|js|png|jpe?g|gif|svg|webp|avif|ico|woff2?)$">
        Header set Cache-Control "public, max-age=31536000, immutable"
    </FilesMatch>
</IfModule>

<IfModule mod_expires.c>
    ExpiresActive On
    ExpiresByType text/css "access plus 1 year"
    ExpiresByType application/javascript "access plus 1 year"
    ExpiresByType text/javascript "access plus 1 year"
    ExpiresByType image/png "access plus 1 year"
    ExpiresByType image/jpeg "access plus 1 year"
    ExpiresByType image/gif "access plus 1 year"
    ExpiresByType image/svg+xml "access plus 1 year"
    ExpiresByType image/webp "access plus 1 year"
    ExpiresByType image/avif "access plus 1 year"
    ExpiresByType image/x-icon "access plus 1 year"
    ExpiresByType font/woff2 "access plus 1 year"
</IfModule>

# --- GZIP sıkıştırma (HTML/CSS/JS/JSON/XML) — Core Web Vitals için kritik ---
# Canlıda pages.css 61KB → gzip'le ~13KB. Hız skoru ve bant genişliği kazancı.
<IfModule mod_deflate.c>
    AddOutputFilterByType DEFLATE text/html text/plain text/xml text/css text/javascript
    AddOutputFilterByType DEFLATE application/javascript application/x-javascript application/json
    AddOutputFilterByType DEFLATE application/rss+xml application/atom+xml image/svg+xml
</IfModule>

# --- HTML için kısa cache (içerik değişebilir), statik varlıklar zaten 1 yıl ---
<IfModule mod_headers.c>
    <FilesMatch "\.(html|php)$">
        Header set Cache-Control "no-cache, must-revalidate"
    </FilesMatch>
    # Security headers (temel set) — 'always' parametresi LiteSpeed'de hata verir, kullanma.
    Header set X-Content-Type-Options "nosniff"
    Header set X-Frame-Options "SAMEORIGIN"
    Header set Referrer-Policy "strict-origin-when-cross-origin"

    # HSTS: HTTPS zorunlu (1 yıl). HTTPS redirect bir üst blokta kesinleşti.
    Header set Strict-Transport-Security "max-age=31536000"

    # Permissions-Policy: site kullanmadigi API'leri kapat.
    Header set Permissions-Policy "geolocation=(), microphone=(), camera=(), payment=(), usb=()"

    # Content-Security-Policy: HAFIF set — GTM/Fonts/Analytics izinli, inline script/style izinli.
    Header set Content-Security-Policy "default-src 'self' https: data: 'unsafe-inline' 'unsafe-eval'; img-src 'self' https: data:; font-src 'self' https: data:; connect-src 'self' https:;"
</IfModule>

