<IfModule mod_php.c>
    php_value pcre.jit 0
</IfModule>

<IfModule mod_setenvif.c>
    # Ensure the Authorization header is available to PHP (JWT Bearer auth).
    SetEnvIfNoCase Authorization "(.+)" HTTP_AUTHORIZATION=$1
</IfModule>

<IfModule mod_headers.c>
    Header set Access-Control-Allow-Origin "*"
</IfModule>

<IfModule mod_rewrite.c>
    <IfModule mod_negotiation.c>
        Options -MultiViews -Indexes
    </IfModule>

    RewriteEngine On

    # Handle Authorization Header (JWT Bearer) when running from the project root.
    # This keeps the API working even if the app is served from a subdirectory (e.g. /saas/saas-api).
    RewriteCond %{HTTP:Authorization} .
    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

    # Map /storage/* to /public/storage/* so files are reachable when the app
    # is served from the project root (not directly from /public as docroot).
    RewriteRule ^storage/(.*)$ public/storage/$1 [L]

    # Requests already targeting /public should be handled there.
    RewriteRule ^public(?:/|$) - [L]

    # Keep local development on plain HTTP.
    RewriteCond %{HTTP_HOST} !^(localhost|127\.0\.0\.1)(:\d+)?$ [NC]
    RewriteCond %{HTTPS} !=on
    RewriteCond %{HTTP:X-Forwarded-Proto} !https [NC]
    RewriteCond %{HTTP:X-Forwarded-SSL} !=on [NC]
    RewriteCond %{HTTP:X-Forwarded-HTTPS} !=on [NC]
    RewriteCond %{HTTP:X-HTTPS} !=1 [NC]
    RewriteCond %{HTTP:CF-Visitor} !\"scheme\":\"https\" [NC]
    RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

    # Forward all application requests to Laravel's front controller.
    # This avoids base-path issues when the app runs in a subdirectory (e.g. /saas/saas-api).
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteRule ^ index.php [L]
</IfModule>
