# Serving the app at https://your-server/cs/ from the default Apache site.
#
# Drop this in /etc/apache2/conf-available/helpdesk.conf and enable it:
#   a2enconf helpdesk && systemctl reload apache2
#
# It assumes:
#   code    /var/www/html/cs
#   uploads /var/lib/helpdesk/uploads   (deliberately OUTSIDE the document root)

# The React build. Anything unknown under /cs falls back to index.html so a
# refresh on /cs/tickets/42 still loads the app.
Alias /cs /var/www/html/cs/web/dist
<Directory /var/www/html/cs/web/dist>
    Require all granted
    AllowOverride None
    Options -Indexes -MultiViews
    FallbackResource /cs/index.html
</Directory>

# The PHP API. This Alias must come after the one above; Apache matches the
# longest prefix, so /cs/api wins over /cs.
Alias /cs/api /var/www/html/cs/api
<Directory /var/www/html/cs/api>
    Require all granted
    AllowOverride None
    Options -Indexes -MultiViews
    FallbackResource /cs/api/index.php

    # Only the front controller is reachable. lib/ and routes/ are include-only.
    <FilesMatch "\.php$">
        Require all denied
    </FilesMatch>
    <Files "index.php">
        Require all granted
    </Files>
</Directory>

# Everything else in the project folder is source, config and CLI scripts.
# None of it should ever be served.
<Directory /var/www/html/cs>
    Require all denied
</Directory>
<Directory /var/www/html/cs/web/src>
    Require all denied
</Directory>

# mod_xsendfile: PHP checks permission, Apache sends the bytes and handles
# HTTP range requests so video can be scrubbed.
XSendFile On
XSendFilePath /var/lib/helpdesk/uploads

<LocationMatch "^/cs/assets/">
    Header set Cache-Control "public, max-age=31536000, immutable"
</LocationMatch>
