# Beyond ICT — generated by tools/package-cpanel.mjs from src/data.mjs. Do not hand-edit:
# change the source and re-package. Built 2026-09-30 for https://beyondict.co.za

Options -Indexes -MultiViews
DirectoryIndex index.html
# /services is both a folder and services.html — serve the page, never redirect to /services/
DirectorySlash Off
ErrorDocument 404 /404.html

<IfModule mod_mime.c>
  AddType video/mp4 .mp4
  AddType video/webm .webm
  AddType image/avif .avif
  AddType image/webp .webp
  AddType image/svg+xml .svg
  AddType font/woff2 .woff2
  AddCharset utf-8 .html .css .js .xml .txt .svg
</IfModule>

<IfModule mod_rewrite.c>
  RewriteEngine On
  RewriteBase /

  # 1. One address: https://beyondict.co.za  (.well-known stays reachable for SSL renewal;
  #    REDIRECT_STATUS: only the visitor's own request, never the internal 404 page)
  RewriteCond %{ENV:REDIRECT_STATUS} ^$
  RewriteCond %{HTTP_HOST} ^www\. [NC]
  RewriteRule ^ https://beyondict.co.za%{REQUEST_URI} [R=301,L,NE]
  RewriteCond %{ENV:REDIRECT_STATUS} ^$
  RewriteCond %{REQUEST_URI} !^/\.well-known/
  RewriteCond %{HTTPS} !=on
  RewriteCond %{HTTP:X-Forwarded-Proto} !https
  RewriteRule ^ https://beyondict.co.za%{REQUEST_URI} [R=301,L,NE]

  # 2. Old WordPress addresses → new pages
  RewriteCond %{THE_REQUEST} \s/+index\.html[\s?]
  RewriteRule ^ https://beyondict.co.za/ [R=301,L]
  RewriteRule ^home(/.*)?$ https://beyondict.co.za/ [R=301,L]
  RewriteRule ^about-us(/.*)?$ https://beyondict.co.za/about [R=301,L]
  RewriteRule ^contact-us(/.*)?$ https://beyondict.co.za/contact [R=301,L]
  RewriteRule ^careers(/.*)?$ https://beyondict.co.za/vacancies [R=301,L]
  RewriteRule ^privacy-policy(/.*)?$ https://beyondict.co.za/privacy [R=301,L]
  RewriteRule ^vbx(/.*)?$ https://beyondict.co.za/services/hosted-pbx [R=301,L]
  RewriteRule ^hosted-pbx(/.*)?$ https://beyondict.co.za/services/hosted-pbx [R=301,L]
  RewriteRule ^sdwan(/.*)?$ https://beyondict.co.za/services/sd-wan [R=301,L]
  RewriteRule ^sd-wan(/.*)?$ https://beyondict.co.za/services/sd-wan [R=301,L]
  RewriteRule ^fibre(/.*)?$ https://beyondict.co.za/services/open-access-fibre [R=301,L]
  RewriteRule ^feed(/.*)?$ https://beyondict.co.za/ [R=301,L]
  RewriteRule ^wp-login\.php(/.*)?$ https://beyondict.co.za/ [R=301,L]
  RewriteRule ^wp-admin(/.*)?$ https://beyondict.co.za/ [R=301,L]

  # 3. Canonical form: /about.html → /about, /services/ → /services
  RewriteCond %{THE_REQUEST} \s/+([^?\s]*?)\.html[\s?]
  RewriteRule ^ https://beyondict.co.za/%1 [R=301,L,NE]
  RewriteCond %{REQUEST_URI} !^/\.well-known/
  RewriteRule ^(.+)/$ https://beyondict.co.za/$1 [R=301,L,NE]

  # 4. Clean URLs: /about → about.html, /services/voice → services/voice.html
  RewriteCond %{REQUEST_FILENAME}.html -f
  RewriteRule ^(.+)$ $1.html [L]
</IfModule>

<IfModule mod_headers.c>
  Header always set X-Content-Type-Options "nosniff"
  Header always set Referrer-Policy "strict-origin-when-cross-origin"
  Header always set X-Frame-Options "SAMEORIGIN"
  Header always set Permissions-Policy "geolocation=(), microphone=(), camera=(), interest-cohort=()"
  # Pages always re-check, so an update shows at once
  <FilesMatch "\.html$">
    Header set Cache-Control "no-cache"
  </FilesMatch>
  # Fingerprinted files (name.0123456789.ext) never change — cache for a year
  <FilesMatch "\.[0-9a-f]{10}\.(css|js|woff2|jpg|webp|avif|mp4|webm)$">
    Header set Cache-Control "public, max-age=31536000, immutable"
  </FilesMatch>
</IfModule>

<IfModule mod_deflate.c>
  AddOutputFilterByType DEFLATE text/html text/css text/javascript application/javascript text/xml application/xml text/plain image/svg+xml
</IfModule>
