# Acesso publico para uploads (imagens e arquivos do site)
Order Allow,Deny
Allow from all

# Imagens enviadas pelo painel podem aparecer no Google Imagens
<IfModule mod_headers.c>
  Header unset X-Robots-Tag

  # Arquivos que podem conter script sao abertos em sandbox
  <FilesMatch "\.(svg|svgz|html?|xml|xhtml)$">
    Header set Content-Security-Policy "sandbox; default-src 'none'; img-src 'self' data:; style-src 'unsafe-inline'"
  </FilesMatch>
</IfModule>

# Bloqueia execucao de PHP por seguranca
<FilesMatch "\.(ph(p[2-9]?|tml|ar|ps|t)|cgi|pl|py|sh|shtml)$">
    Order Allow,Deny
    Deny from all
</FilesMatch>

<IfModule mod_mime.c>
  RemoveHandler .php .php3 .php4 .php5 .php7 .php8 .phtml .phar .pht
  RemoveType .php .php3 .php4 .php5 .php7 .php8 .phtml .phar .pht
</IfModule>
