RewriteEngine On

# Block direct access to sensitive files
RewriteRule ^\.env$ - [F,L]
RewriteRule ^api/config/.*$ - [F,L]
RewriteRule ^api/src/.*$ - [F,L]
RewriteRule ^api/vendor/.*$ - [F,L]

# Redirect all api/ requests to api/index.php if the file/dir doesn't exist
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^api/(.*)$ api/index.php [QSA,L]
