jasteele123

concrete5 .htaccess

May 30th, 2012
134
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.80 KB | None | 0 0
  1. # -- concrete5 urls start --
  2. <IfModule mod_rewrite.c>
  3. RewriteEngine On
  4. RewriteBase /
  5. RewriteCond %{REQUEST_FILENAME} !-f
  6. RewriteCond %{REQUEST_FILENAME}/index.html !-f
  7. RewriteCond %{REQUEST_FILENAME}/index.php !-f
  8. RewriteRule . index.php [L]
  9. </IfModule>
  10. # -- concrete5 urls end --
  11.  
  12. # ----------------------------------------------------------------------
  13. # Better website experience for IE users
  14. # ----------------------------------------------------------------------
  15.  
  16. # Force the latest IE version, in various cases when it may fall back to IE7 mode
  17. # github.com/rails/rails/commit/123eb25#commitcomment-118920
  18. # Use ChromeFrame if it's installed for a better experience for the poor IE folk
  19.  
  20. <IfModule mod_headers.c>
  21. Header set X-UA-Compatible "IE=Edge,chrome=1"
  22. # mod_headers can't match by content-type, but we don't want to send this header on *everything*...
  23. <FilesMatch "\.(js|css|gif|png|jpe?g|pdf|xml|oga|ogg|m4a|ogv|mp4|m4v|webm|svg|svgz|eot|ttf|otf|woff|ico|webp|appcache|manifest|htc|crx|oex|xpi|safariextz|vcf)$" >
  24. Header unset X-UA-Compatible
  25. </FilesMatch>
  26. </IfModule>
  27.  
  28. # ----------------------------------------------------------------------
  29. # Cross-domain AJAX requests
  30. # ----------------------------------------------------------------------
  31.  
  32. # Serve cross-domain Ajax requests, disabled by default.
  33. # enable-cors.org
  34. # code.google.com/p/html5security/wiki/CrossOriginRequestSecurity
  35.  
  36. <IfModule mod_headers.c>
  37. Header set Access-Control-Allow-Origin "*"
  38. </IfModule>
  39.  
  40. # ----------------------------------------------------------------------
  41. # CORS-enabled images (@crossorigin)
  42. # ----------------------------------------------------------------------
  43.  
  44. # Send CORS headers if browsers request them; enabled by default for images.
  45. # developer.mozilla.org/en/CORS_Enabled_Image
  46. # blog.chromium.org/2011/07/using-cross-domain-images-in-webgl-and.html
  47. # hacks.mozilla.org/2011/11/using-cors-to-load-webgl-textures-from-cross-domain-images/
  48. # wiki.mozilla.org/Security/Reviews/crossoriginAttribute
  49.  
  50. <IfModule mod_setenvif.c>
  51. <IfModule mod_headers.c>
  52. # mod_headers, y u no match by Content-Type?!
  53. <FilesMatch "\.(gif|png|jpe?g|svg|svgz|ico|webp)$">
  54. SetEnvIf Origin ":" IS_CORS
  55. Header set Access-Control-Allow-Origin "*" env=IS_CORS
  56. </FilesMatch>
  57. </IfModule>
  58. </IfModule>
  59.  
  60.  
  61. # ----------------------------------------------------------------------
  62. # Webfont access
  63. # ----------------------------------------------------------------------
  64.  
  65. # Allow access from all domains for webfonts.
  66. # Alternatively you could only whitelist your
  67. # subdomains like "subdomain.example.com".
  68.  
  69. <IfModule mod_headers.c>
  70. <FilesMatch "\.(ttf|ttc|otf|eot|woff|font.css)$">
  71. Header set Access-Control-Allow-Origin "*"
  72. </FilesMatch>
  73. </IfModule>
  74.  
  75.  
  76. # ----------------------------------------------------------------------
  77. # Proper MIME type for all files
  78. # ----------------------------------------------------------------------
  79.  
  80.  
  81. # JavaScript
  82. # Normalize to standard type (it's sniffed in IE anyways)
  83. # tools.ietf.org/html/rfc4329#section-7.2
  84. AddType application/javascript js
  85.  
  86. # Audio
  87. AddType audio/ogg oga ogg
  88. AddType audio/mp4 m4a
  89.  
  90. # Video
  91. AddType video/ogg ogv
  92. AddType video/mp4 mp4 m4v
  93. AddType video/webm webm
  94.  
  95. # SVG
  96. # Required for svg webfonts on iPad
  97. # twitter.com/FontSquirrel/status/14855840545
  98. AddType image/svg+xml svg svgz
  99. AddEncoding gzip svgz
  100.  
  101. # Webfonts
  102. AddType application/vnd.ms-fontobject eot
  103. AddType application/x-font-ttf ttf ttc
  104. AddType font/opentype otf
  105. AddType application/x-font-woff woff
  106.  
  107. # Assorted types
  108. AddType image/x-icon ico
  109. AddType image/webp webp
  110. AddType text/cache-manifest appcache manifest
  111. AddType text/x-component htc
  112. AddType application/x-chrome-extension crx
  113. AddType application/x-opera-extension oex
  114. AddType application/x-xpinstall xpi
  115. AddType application/octet-stream safariextz
  116. AddType application/x-web-app-manifest+json webapp
  117. AddType text/x-vcard vcf
  118.  
  119.  
  120.  
  121. # ----------------------------------------------------------------------
  122. # Allow concatenation from within specific js and css files
  123. # ----------------------------------------------------------------------
  124.  
  125. # e.g. Inside of script.combined.js you could have
  126. # <!--#include file="libs/jquery-1.5.0.min.js" -->
  127. # <!--#include file="plugins/jquery.idletimer.js" -->
  128. # and they would be included into this single file.
  129.  
  130. # This is not in use in the boilerplate as it stands. You may
  131. # choose to name your files in this way for this advantage or
  132. # concatenate and minify them manually.
  133. # Disabled by default.
  134.  
  135. #<FilesMatch "\.combined\.js$">
  136. # Options +Includes
  137. # AddOutputFilterByType INCLUDES application/javascript application/json
  138. # SetOutputFilter INCLUDES
  139. #</FilesMatch>
  140. #<FilesMatch "\.combined\.css$">
  141. # Options +Includes
  142. # AddOutputFilterByType INCLUDES text/css
  143. # SetOutputFilter INCLUDES
  144. #</FilesMatch>
  145.  
  146.  
  147. # ----------------------------------------------------------------------
  148. # Gzip compression
  149. # ----------------------------------------------------------------------
  150.  
  151. <IfModule mod_deflate.c>
  152.  
  153. # Force deflate for mangled headers developer.yahoo.com/blogs/ydn/posts/2010/12/pushing-beyond-gzipping/
  154. <IfModule mod_setenvif.c>
  155. <IfModule mod_headers.c>
  156. SetEnvIfNoCase ^(Accept-EncodXng|X-cept-Encoding|X{15}|~{15}|-{15})$ ^((gzip|deflate)\s*,?\s*)+|[X~-]{4,13}$ HAVE_Accept-Encoding
  157. RequestHeader append Accept-Encoding "gzip,deflate" env=HAVE_Accept-Encoding
  158. </IfModule>
  159. </IfModule>
  160.  
  161. # HTML, TXT, CSS, JavaScript, JSON, XML, HTC:
  162. <IfModule filter_module>
  163. FilterDeclare COMPRESS
  164. FilterProvider COMPRESS DEFLATE resp=Content-Type $text/html
  165. FilterProvider COMPRESS DEFLATE resp=Content-Type $text/css
  166. FilterProvider COMPRESS DEFLATE resp=Content-Type $text/plain
  167. FilterProvider COMPRESS DEFLATE resp=Content-Type $text/xml
  168. FilterProvider COMPRESS DEFLATE resp=Content-Type $text/x-component
  169. FilterProvider COMPRESS DEFLATE resp=Content-Type $application/javascript
  170. FilterProvider COMPRESS DEFLATE resp=Content-Type $application/json
  171. FilterProvider COMPRESS DEFLATE resp=Content-Type $application/xml
  172. FilterProvider COMPRESS DEFLATE resp=Content-Type $application/xhtml+xml
  173. FilterProvider COMPRESS DEFLATE resp=Content-Type $application/rss+xml
  174. FilterProvider COMPRESS DEFLATE resp=Content-Type $application/atom+xml
  175. FilterProvider COMPRESS DEFLATE resp=Content-Type $application/vnd.ms-fontobject
  176. FilterProvider COMPRESS DEFLATE resp=Content-Type $image/svg+xml
  177. FilterProvider COMPRESS DEFLATE resp=Content-Type $image/x-icon
  178. FilterProvider COMPRESS DEFLATE resp=Content-Type $application/x-font-ttf
  179. FilterProvider COMPRESS DEFLATE resp=Content-Type $font/opentype
  180. FilterChain COMPRESS
  181. FilterProtocol COMPRESS DEFLATE change=yes;byteranges=no
  182. </IfModule>
  183.  
  184. <IfModule !mod_filter.c>
  185. # Legacy versions of Apache
  186. AddOutputFilterByType DEFLATE text/html text/plain text/css application/json
  187. AddOutputFilterByType DEFLATE application/javascript
  188. AddOutputFilterByType DEFLATE text/xml application/xml text/x-component
  189. AddOutputFilterByType DEFLATE application/xhtml+xml application/rss+xml application/atom+xml
  190. AddOutputFilterByType DEFLATE image/x-icon image/svg+xml application/vnd.ms-fontobject application/x-font-ttf font/opentype
  191. </IfModule>
  192.  
  193. </IfModule>
  194.  
  195.  
  196. # ----------------------------------------------------------------------
  197. # Expires headers (for better cache control)
  198. # ----------------------------------------------------------------------
  199.  
  200. # These are pretty far-future expires headers.
  201. # They assume you control versioning with cachebusting query params like
  202. # <script src="application.js?20100608">
  203. # Additionally, consider that outdated proxies may miscache
  204. # www.stevesouders.com/blog/2008/08/23/revving-filenames-dont-use-querystring/
  205.  
  206. # If you don't use filenames to version, lower the CSS and JS to something like
  207. # "access plus 1 week" or so.
  208.  
  209. <IfModule mod_expires.c>
  210. ExpiresActive on
  211.  
  212. # Perhaps better to whitelist expires rules? Perhaps.
  213. ExpiresDefault "access plus 1 month"
  214.  
  215. # cache.appcache needs re-requests in FF 3.6 (thanks Remy ~Introducing HTML5)
  216. ExpiresByType text/cache-manifest "access plus 0 seconds"
  217.  
  218. # Your document html
  219. ExpiresByType text/html "access plus 0 seconds"
  220.  
  221. # Data
  222. ExpiresByType text/xml "access plus 0 seconds"
  223. ExpiresByType application/xml "access plus 0 seconds"
  224. ExpiresByType application/json "access plus 0 seconds"
  225.  
  226. # Feed
  227. ExpiresByType application/rss+xml "access plus 1 hour"
  228. ExpiresByType application/atom+xml "access plus 1 hour"
  229.  
  230. # Favicon (cannot be renamed)
  231. ExpiresByType image/x-icon "access plus 1 week"
  232.  
  233. # Media: images, video, audio
  234. ExpiresByType image/gif "access plus 1 month"
  235. ExpiresByType image/png "access plus 1 month"
  236. ExpiresByType image/jpg "access plus 1 month"
  237. ExpiresByType image/jpeg "access plus 1 month"
  238. ExpiresByType video/ogg "access plus 1 month"
  239. ExpiresByType audio/ogg "access plus 1 month"
  240. ExpiresByType video/mp4 "access plus 1 month"
  241. ExpiresByType video/webm "access plus 1 month"
  242.  
  243. # HTC files (css3pie)
  244. ExpiresByType text/x-component "access plus 1 month"
  245.  
  246. # Webfonts
  247. ExpiresByType application/x-font-ttf "access plus 1 month"
  248. ExpiresByType font/opentype "access plus 1 month"
  249. ExpiresByType application/x-font-woff "access plus 1 month"
  250. ExpiresByType image/svg+xml "access plus 1 month"
  251. ExpiresByType application/vnd.ms-fontobject "access plus 1 month"
  252.  
  253. # CSS and JavaScript
  254. ExpiresByType text/css "access plus 1 year"
  255. ExpiresByType application/javascript "access plus 1 year"
  256.  
  257. </IfModule>
  258.  
  259.  
  260.  
  261. # ----------------------------------------------------------------------
  262. # ETag removal
  263. # ----------------------------------------------------------------------
  264.  
  265. # FileETag None is not enough for every server.
  266. <IfModule mod_headers.c>
  267. Header unset ETag
  268. </IfModule>
  269.  
  270. # Since we're sending far-future expires, we don't need ETags for
  271. # static content.
  272. # developer.yahoo.com/performance/rules.html#etags
  273. FileETag None
  274.  
  275. # ----------------------------------------------------------------------
  276. # Built-in filename-based cache busting
  277. # ----------------------------------------------------------------------
  278.  
  279. # If you're not using the build script to manage your filename version revving,
  280. # you might want to consider enabling this, which will route requests for
  281. # /css/style.20110203.css to /css/style.css
  282.  
  283. # To understand why this is important and a better idea than all.css?v1231,
  284. # read: github.com/h5bp/html5-boilerplate/wiki/Version-Control-with-Cachebusting
  285.  
  286. # Uncomment to enable.
  287. <IfModule mod_rewrite.c>
  288. RewriteCond %{REQUEST_FILENAME} !-f
  289. RewriteCond %{REQUEST_FILENAME} !-d
  290. RewriteRule ^(.+)\.(\d+)\.(js|css|png|jpg|gif)$ $1.$3 [L]
  291. </IfModule>
  292.  
  293. <IfModule mod_rewrite.c>
  294. RewriteCond %{REQUEST_URI} ^/css/cache
  295. RewriteCond %{REQUEST_FILENAME} !-f
  296. RewriteRule ^css/cache/(.*)$ /css/csscacher.php?files=$1 [L]
  297. </IfModule>
  298.  
  299. # ----------------------------------------------------------------------
  300. # Stop screen flicker in IE on CSS rollovers
  301. # ----------------------------------------------------------------------
  302.  
  303. # The following directives stop screen flicker in IE on CSS rollovers - in
  304. # combination with the "ExpiresByType" rules for images (see above). If
  305. # needed, un-comment the following rules.
  306.  
  307. # BrowserMatch "MSIE" brokenvary=1
  308. # BrowserMatch "Mozilla/4.[0-9]{2}" brokenvary=1
  309. # BrowserMatch "Opera" !brokenvary
  310. # SetEnvIf brokenvary 1 force-no-vary
  311.  
  312.  
  313.  
  314. # ----------------------------------------------------------------------
  315. # Cookie setting from iframes
  316. # ----------------------------------------------------------------------
  317.  
  318. # Allow cookies to be set from iframes (for IE only)
  319. # If needed, uncomment and specify a path or regex in the Location directive
  320.  
  321. # <IfModule mod_headers.c>
  322. # <Location />
  323. # Header set P3P "policyref=\"/w3c/p3p.xml\", CP=\"IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT\""
  324. # </Location>
  325. # </IfModule>
  326. # Increase cookie security
  327. <IfModule php5_module>
  328. php_value session.cookie_httponly true
  329. </IfModule>
Advertisement
Add Comment
Please, Sign In to add comment