# ========================= # FORCE HTTPS # ========================= RewriteEngine On RewriteCond %{REQUEST_URI} ^/info/?$ [NC] RewriteCond %{QUERY_STRING} (^|&)search= [NC] RewriteRule .* - [G,L] RewriteCond %{HTTPS} off RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] # ========================= # SECURITY HEADERS # ========================= <IfModule mod_headers.c> Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" Header always set X-Frame-Options "SAMEORIGIN" Header always set X-Content-Type-Options "nosniff" Header always set Referrer-Policy "strict-origin-when-cross-origin" Header always set Permissions-Policy "geolocation=(), microphone=(), camera=()" Header always set Content-Security-Policy "default-src 'self' https: data: 'unsafe-inline' 'unsafe-eval';" </IfModule>