# RAD Ensemble — Apache config
Options -Indexes
# PHP mail protection — only allow POST to send_mail.php from same origin
Require all denied
# Cache static assets
ExpiresActive On
ExpiresByType image/svg+xml "access plus 1 month"
ExpiresByType text/css "access plus 1 week"
ExpiresByType application/javascript "access plus 1 week"
# GZIP compression
AddOutputFilterByType DEFLATE text/html text/css application/javascript image/svg+xml
# Security headers
Header always set X-Content-Type-Options nosniff
Header always set X-Frame-Options SAMEORIGIN
Header always set Referrer-Policy strict-origin-when-cross-origin
# Default to index.html
DirectoryIndex index.html