# RAD Ensemble — Apache config Options -Indexes # PHP mail protection — only allow POST to send_mail.php from same origin Require all denied # Cache static assets ExpiresActive On ExpiresByType image/svg+xml "access plus 1 month" ExpiresByType text/css "access plus 1 week" ExpiresByType application/javascript "access plus 1 week" # GZIP compression AddOutputFilterByType DEFLATE text/html text/css application/javascript image/svg+xml # Security headers Header always set X-Content-Type-Options nosniff Header always set X-Frame-Options SAMEORIGIN Header always set Referrer-Policy strict-origin-when-cross-origin # Default to index.html DirectoryIndex index.html