# Enable rewrite engine
RewriteEngine On

# Redirect to HTTPS (optional, uncomment if needed)
# RewriteCond %{HTTPS} off
# RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

# Remove .php extension
# If the request is for a file that exists with .php extension
RewriteCond %{REQUEST_FILENAME} !-d
RewriteCond %{REQUEST_FILENAME}\.php -f
RewriteRule ^(.*)$ $1.php [L]

# Redirect .php URLs to non-.php URLs
RewriteCond %{THE_REQUEST} ^GET\ /(.*)\.php\ HTTP
RewriteRule (.*)\.php$ /$1 [R=301,L]

# Remove trailing slash (optional)
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^(.*)/$ /$1 [R=301,L]

# Error documents (optional)
# ErrorDocument 404 /404.php
# ErrorDocument 403 /403.php
# ErrorDocument 500 /500.php

# Security settings
# Disable directory browsing
Options -Indexes

# Prevent access to .htaccess file
<Files .htaccess>
    Order allow,deny
    Deny from all
</Files>

# Prevent access to sensitive files
<FilesMatch "\.(htaccess|htpasswd|ini|log|sh|sql|bak|config)$">
    Order allow,deny
    Deny from all
</FilesMatch>
