# ============================================
# SPEED PANEL - .htaccess الرئيسي
# ============================================

<IfModule mod_rewrite.c>
    <IfModule mod_negotiation.c>
        Options -MultiViews -Indexes
    </IfModule>

    RewriteEngine On

    # ============================================
    # Handle Authorization Header
    # ============================================
    RewriteCond %{HTTP:Authorization} .
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

    # ============================================
    # Redirect Trailing Slashes If Not A Folder...
    # ============================================
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteCond %{REQUEST_URI} (.+)/$
    RewriteRule ^ %1 [L,R=301]

    # ============================================
    # Send Requests To Front Controller...
    # ============================================
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteRule ^ index.php [L]
</IfModule>

# ============================================
# Security Headers
# ============================================
<IfModule mod_headers.c>
    # حماية XSS
    Header set X-XSS-Protection "1; mode=block"
    
    # منع تحميل الصفحة في إطار (Clickjacking)
    Header set X-Frame-Options "DENY"
    
    # منع تخمين نوع الملفات
    Header set X-Content-Type-Options "nosniff"
    
    # سياسة الإحالة
    Header set Referrer-Policy "strict-origin-when-cross-origin"
    
    # سياسة الأذونات
    Header set Permissions-Policy "geolocation=(), microphone=(), camera=()"
    
    # سياسة أمان المحتوى (CSP)
    Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://unpkg.com https://www.google.com https://www.gstatic.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://ui-avatars.com https://storage.perfectcdn.com; connect-src 'self' https://www.googleapis.com; frame-src 'self' https://accounts.google.com;"
</IfModule>

# ============================================
# Compression (Gzip)
# ============================================
<IfModule mod_deflate.c>
    # ضغط النصوص
    AddOutputFilterByType DEFLATE text/html text/plain text/xml text/css text/javascript application/javascript application/x-javascript application/json application/xml application/rss+xml application/atom+xml
    
    # ضغط الخطوط
    AddOutputFilterByType DEFLATE font/ttf font/otf image/svg+xml
    
    # استثناء الملفات الصغيرة
    SetEnvIfNoCase Request_URI \.(?:gif|jpe?g|png|ico|zip|gz|rar|pdf|mp3|mp4|avi|mov|wmv|flv)$ no-gzip dont-vary
</IfModule>

# ============================================
# Cache Control (تخزين مؤقت)
# ============================================
<IfModule mod_expires.c>
    ExpiresActive On
    
    # الصور - سنة
    ExpiresByType image/jpg "access plus 1 year"
    ExpiresByType image/jpeg "access plus 1 year"
    ExpiresByType image/gif "access plus 1 year"
    ExpiresByType image/png "access plus 1 year"
    ExpiresByType image/webp "access plus 1 year"
    ExpiresByType image/svg+xml "access plus 1 year"
    ExpiresByType image/ico "access plus 1 year"
    
    # CSS و JS - شهر
    ExpiresByType text/css "access plus 1 month"
    ExpiresByType text/javascript "access plus 1 month"
    ExpiresByType application/javascript "access plus 1 month"
    ExpiresByType application/x-javascript "access plus 1 month"
    
    # الخطوط - سنة
    ExpiresByType font/ttf "access plus 1 year"
    ExpiresByType font/otf "access plus 1 year"
    ExpiresByType font/woff "access plus 1 year"
    ExpiresByType font/woff2 "access plus 1 year"
    
    # HTML - لا تخزين
    ExpiresByType text/html "access plus 0 seconds"
    ExpiresByType application/json "access plus 0 seconds"
</IfModule>

# ============================================
# Prevent Directory Listing
# ============================================
Options -Indexes

# ============================================
# Protect Sensitive Files
# ============================================
<FilesMatch "^\.">
    Order allow,deny
    Deny from all
</FilesMatch>

<FilesMatch "\.(env|log|sql|sqlite|json|lock|yaml|yml|ini|conf|config|php~|php_|php_bak|phtml)$">
    Order allow,deny
    Deny from all
</FilesMatch>

<FilesMatch "^(composer\.json|composer\.lock|package\.json|package-lock\.json|webpack\.mix\.js|vite\.config\.js|tailwind\.config\.js|postcss\.config\.js|artisan|server\.php)$">
    Order allow,deny
    Deny from all
</FilesMatch>

# ============================================
# Protect .env File
# ============================================
<Files .env>
    Order allow,deny
    Deny from all
</Files>

# ============================================
# Protect .htaccess Itself
# ============================================
<Files .htaccess>
    Order allow,deny
    Deny from all
</Files>

# ============================================
# PHP Settings
# ============================================
<IfModule mod_php8.c>
    php_value upload_max_filesize 20M
    php_value post_max_size 20M
    php_value max_execution_time 300
    php_value memory_limit 51200M
    php_value max_input_time 300
    php_value max_input_vars 5000
</IfModule>

<IfModule mod_php7.c>
    php_value upload_max_filesize 20M
    php_value post_max_size 20M
    php_value max_execution_time 300
    php_value memory_limit 51200M
    php_value max_input_time 300
    php_value max_input_vars 5000
</IfModule>

<IfModule mod_php.c>
    php_value upload_max_filesize 20M
    php_value post_max_size 20M
    php_value max_execution_time 300
    php_value memory_limit 51200M
    php_value max_input_time 300
    php_value max_input_vars 5000
</IfModule>

# ============================================
# Handle PHP Extensions
# ============================================
<FilesMatch "\.(php|phtml)$">
    <IfModule mod_headers.c>
        Header set X-Content-Type-Options "nosniff"
    </IfModule>
</FilesMatch>

# ============================================
# Error Pages (مخصصة)
# ============================================
ErrorDocument 404 /index.php
ErrorDocument 403 /index.php
ErrorDocument 500 /index.php
ErrorDocument 503 /index.php

# ============================================
# Redirect HTTP to HTTPS (للإنتاج)
# ============================================
<IfModule mod_rewrite.c>
    RewriteCond %{HTTPS} off
    RewriteCond %{HTTP_HOST} !^localhost
    RewriteCond %{HTTP_HOST} !^127\.0\.0\.1
    RewriteCond %{HTTP_HOST} !^192\.168\.
    RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
</IfModule>

# ============================================
# Block Bad Bots (حماية من البوتات الضارة)
# ============================================
<IfModule mod_rewrite.c>
    RewriteCond %{HTTP_USER_AGENT} (ahrefs|semrush|majestic|rogerbot|dotbot|sitebot|spider|scraper) [NC]
    RewriteRule .* - [F,L]
</IfModule>

# ============================================
# Allow Google Bot Only (اختياري)
# ============================================
<IfModule mod_rewrite.c>
    RewriteCond %{HTTP_USER_AGENT} !(Googlebot|Bingbot|Slurp|DuckDuckBot|Baiduspider|YandexBot|facebookexternalhit|Twitterbot) [NC]
    RewriteCond %{REQUEST_URI} !^/robots\.txt$
    RewriteCond %{REQUEST_URI} !^/sitemap\.xml$
    RewriteCond %{REQUEST_URI} !^/favicon\.ico$
    # RewriteRule .* - [F,L]  # إلغاء التعليق لو عايز تمنع البوتات غير المعروفة
</IfModule>

# ============================================
# Protect Vendor Folder
# ============================================
<IfModule mod_rewrite.c>
    RewriteRule ^vendor/.*$ - [F,L]
</IfModule>

# ============================================
# Protect Storage Folder
# ============================================
<IfModule mod_rewrite.c>
    RewriteRule ^storage/.*$ - [F,L]
</IfModule>

# ============================================
# Protect Database Folder
# ============================================
<IfModule mod_rewrite.c>
    RewriteRule ^database/.*$ - [F,L]
</IfModule>

# CORS Headers
<IfModule mod_headers.c>
    Header set Access-Control-Allow-Origin "*"
    Header set Access-Control-Allow-Methods "GET, POST, OPTIONS"
    Header set Access-Control-Allow-Headers "Content-Type, Authorization, X-Requested-With"
</IfModule>

# ============================================
# Content Security Policy - متوافق مع SMS-Kash
# ============================================
<IfModule mod_headers.c>
    Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://cdn.jsdelivr.net https://unpkg.com https://www.google.com https://www.gstatic.com https://sms-kash.com; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com; font-src 'self' https://fonts.gstatic.com; img-src 'self' data: https://ui-avatars.com https://storage.perfectcdn.com https://www.shutterstock.com https://sms-kash.com; connect-src 'self' https://www.googleapis.com https://sms-kash.com; frame-src 'self' https://accounts.google.com;"
</IfModule>