# MCQ Portal - document root
Options -Indexes

<IfModule mod_rewrite.c>
    RewriteEngine On
    # Block direct web access to sensitive folders
    RewriteRule ^(?:config|includes|sql)(?:/|$) - [F,L]
</IfModule>

# Block sensitive file types if requested directly
<FilesMatch "\.(sql|md|ini|log)$">
    <IfModule mod_authz_core.c>
        Require all denied
    </IfModule>
    <IfModule !mod_authz_core.c>
        Order deny,allow
        Deny from all
    </IfModule>
</FilesMatch>
