# ANNU KUTE CED — configuration Apache (o2switch) # Forcer HTTPS RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] # Redirections des anciennes URLs PHP RedirectMatch 301 ^/index\.php.*$ / RedirectMatch 301 ^/direct\.php.*$ /direct/ RedirectMatch 301 ^/dons\.php.*$ /dons/ RedirectMatch 301 ^/mentions-legales\.php.*$ /mentions-legales/ RewriteRule ^video\.php\?uuid=([A-Za-z0-9]+).*$ /video/$1/ [R=301,L,QSD] RewriteRule ^categories\.php\?id=([0-9]+).*$ /categories/$1/ [R=301,L,QSD] RewriteRule ^recherche\.php\?q=(.*)$ /recherche/?q=$1 [R=301,L] # Page 404 ErrorDocument 404 /404.html # Headers de sécurité Header always set Content-Security-Policy "style-src 'self' 'unsafe-inline'; img-src 'self' data: https://gade.o-k-i.net https://kute.o-k-i.net https://bokante.o-k-i.net; font-src 'self'; connect-src 'self'; media-src 'self' https://gade.o-k-i.net https://kute.o-k-i.net https://bokante.o-k-i.net; frame-src https://gade.o-k-i.net; frame-ancestors 'none'; base-uri 'self'; form-action 'self'; object-src 'none'" Header always set Strict-Transport-Security "max-age=31536000" Header always set X-Frame-Options "DENY" Header always set X-Content-Type-Options "nosniff" Header always set Referrer-Policy "strict-origin-when-cross-origin" Header always set Permissions-Policy "accelerometer=(), camera=(), geolocation=(), gyroscope=(), magnetometer=(), microphone=(), payment=(), usb=()" # Cache immutable des assets fingerprintés et des fonts ExpiresActive On ExpiresByType font/woff2 "access plus 1 year" ExpiresByType image/png "access plus 1 week" ExpiresByType image/x-icon "access plus 1 week" RewriteCond %{REQUEST_URI} ^/(_app|fonts)/ [NC] RewriteRule .* - [E=CACHE_IMMUTABLE:1] Header set Cache-Control "public, max-age=31536000, immutable" env=CACHE_IMMUTABLE