RewriteEngine On # Prevent direct access to sensitive configuration and source folders RewriteRule ^(\.env|\.git|database|docker|tests|scripts|config|app|vendor|docker-compose\.yml|composer\.(json|lock)|phpunit\.xml) - [F,L,NC] # Pass Authorization header to PHP for JWT RewriteCond %{HTTP:Authorization} . RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] # Stop rewriting if the request is already inside public/ RewriteRule ^public/ - [L] # If the requested file or folder exists in root, serve it directly RewriteCond %{REQUEST_FILENAME} -f [OR] RewriteCond %{REQUEST_FILENAME} -d RewriteRule ^ - [L] # Otherwise, forward all requests into public/ RewriteRule ^(.*)$ public/$1 [L,QSA]