# ITSWEBER CMS – uploads hardening
#
# SVG files may contain legitimate markup but are also a classic XSS vector
# when opened directly in a browser (the browser treats them as top-level HTML).
# Even though SvgSanitizer rewrites every uploaded SVG, this adds defense-in-depth
# for any file that slipped in before the fix or through a future regression.

<IfModule mod_headers.c>
    <FilesMatch "\.svg$">
        Header set Content-Security-Policy "default-src 'none'; style-src 'unsafe-inline'; img-src data:"
        Header set X-Content-Type-Options "nosniff"
    </FilesMatch>
</IfModule>

# Block direct execution of anything that should not run as code in the upload tree.
<FilesMatch "\.(php|phtml|phar|pl|py|cgi|sh|asp|aspx|jsp|exe)$">
    Require all denied
</FilesMatch>

# Uploads keep their file name when an image is replaced: cache 30 days
# instead of the year that applies to versioned theme assets.
<IfModule mod_expires.c>
    <FilesMatch "\.(png|jpe?g|gif|webp|avif|svg|ico|pdf)$">
        ExpiresDefault "access plus 30 days"
    </FilesMatch>
</IfModule>
<IfModule mod_headers.c>
    <FilesMatch "\.(png|jpe?g|gif|webp|avif|svg|ico|pdf|zip)$">
        Header set Cache-Control "public, max-age=2592000"
        Header set X-Content-Type-Options "nosniff"
    </FilesMatch>
</IfModule>
