# File: /.htaccess (Root Directory)

# 1. Matikan fitur "intip folder" (Directory Listing)
Options -Indexes

# 2. Sembunyikan identitas server dari attacker
ServerSignature Off

# 3. Buka jalur komunikasi lintas domain (CORS) untuk modul mikrokontroler
<IfModule mod_headers.c>
    Header set Access-Control-Allow-Origin "*"
    Header set Access-Control-Allow-Methods "GET, POST, PUT, DELETE, OPTIONS"
    Header set Access-Control-Allow-Headers "Content-Type, Authorization, X-Requested-With"
</IfModule>

# 4. Memaksa Session agar Tidak Logout Saat Tutup Browser
<IfModule mod_php.c>
    php_value session.cookie_lifetime 31536000
    php_value session.gc_maxlifetime 31536000
</IfModule>
<IfModule mod_php7.c>
    php_value session.cookie_lifetime 31536000
    php_value session.gc_maxlifetime 31536000
</IfModule>
<IfModule mod_php8.c>
    php_value session.cookie_lifetime 31536000
    php_value session.gc_maxlifetime 31536000
</IfModule>