# Block ALL web access to the application directory.
#
# Written for BOTH Apache generations on purpose. The previous version used only
# the 2.2 form (`Order deny,allow` / `Deny from all`), which Apache 2.4 honours
# only when mod_access_compat is loaded - and a host that has not loaded it
# either 500s or, depending on configuration, ignores the file. Guarding PHI on
# "whichever modules this shared host happens to enable" is not a control.
#
# Defence in depth only: participant documents are no longer stored under
# public_html at all (see UPLOAD_DIR in deploy/cpanel/terminal-install.sh). This
# file exists so that application source, .env and secrets in this directory
# stay unreachable even if that ever regresses.
<IfModule mod_authz_core.c>
    # Apache 2.4+
    Require all denied
</IfModule>
<IfModule !mod_authz_core.c>
    # Apache 2.2
    Order deny,allow
    Deny from all
</IfModule>
