DirectoryIndex index.php
Options -Indexes
RewriteEngine On

# Set COOP policy to allow Google OAuth popups to send postMessage
<IfModule mod_headers.c>
    Header set Cross-Origin-Opener-Policy "same-origin-allow-popups"
</IfModule>

# 1. Block direct access to sensitive core directories
RewriteCond %{REQUEST_URI} !^/(?:nexserve/)?vendor/.* [NC]
RewriteRule ^(config|core|database|vendor)/ - [F,L]

# 2. Allow assets and uploads to pass through directly
RewriteCond %{REQUEST_URI} ^/(?:nexserve/)?(assets|uploads)/ [NC]
RewriteRule ^ - [L]

# 3. Shortened key public URLs
RewriteRule ^login$ public/login.php [NC,L]
RewriteRule ^logout$ public/logout.php [NC,L]
RewriteRule ^register$ public/register.php [NC,L]
RewriteRule ^forgot-password$ public/forgot-password.php [NC,L]
RewriteRule ^change-password$ public/change_password.php [NC,L]
RewriteRule ^lock$ public/lock.php [NC,L]
RewriteRule ^track$ public/track.php [NC,L]
RewriteRule ^switch-dashboard$ public/switch_dashboard.php [NC,L]
RewriteRule ^store/([a-zA-Z0-9_-]+)$ public/storefront.php?slug=$1 [NC,L]
RewriteRule ^store/([a-zA-Z0-9_-]+)/checkout$ public/checkout.php?slug=$1 [NC,L]

# 4. Shorten module folder paths (e.g., /owner/dashboard -> modules/owner/dashboard)
RewriteRule ^(superadmin|owner|manager|cashier|waiter|chef|rider)/(.*)$ modules/$1/$2 [NC,L]

# 5. Generic extensionless PHP files mapping (covers all standard pages and API endpoints)
RewriteCond %{REQUEST_FILENAME} !-d
RewriteCond %{REQUEST_FILENAME}.php -f
RewriteRule ^([^\.]+)$ $1.php [NC,L]
