<IfModule mod_rewrite.c>
RewriteEngine On
# Reindirizza il traffico HTTP a HTTPS
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
# Reindirizza il traffico HTTPS a HTTP
RewriteCond %{HTTPS} =on
RewriteRule ^ http://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
</IfModule>
<FilesMatch "\.(html|htm)$">
Header set Cache-Control "public, max-age=864000, immutable"
</FilesMatch>
<FilesMatch "\.(jpg|jpeg|png|gif)$">
Header set Cache-Control "max-age=864000, public"
</FilesMatch>
<IfModule mod_headers.c>
Header always set Strict-Transport-Security "max-age=864000; includeSubDomains; preload"
Header set X-UA-Compatible "IE=edge"
Header set Cache-Control "public, max-age=864000, immutable"
Header set X-XSS-Protection "1; mode=block"
Header set X-Frame-Options "DENY"
Header always set Content-Security-Policy "object-src 'none'; base-uri 'none'; img-src https: data:; form-action 'none' 'self';"
Header set Content-Security-Policy "frame-ancestors 'self' https://xxxx.altervista.org"
Header set Referrer-Policy "strict-origin-when-cross-origin"
Header set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
</IfModule>
<IfModule mod_cache.c>
CacheMaxFileSize 400K # Imposta la dimensione massima della cache a 400 kB
CacheMaxExpire 86400 # Imposta la durata massima della cache a 1 giorno
</IfModule>
<IfModule mod_deflate.c>
# Abilita la compressione Gzip per i file JavaScript
AddOutputFilterByType DEFLATE application/javascript
</IfModule>
<Directory /vat/html/www>
# politica di sicurezza CORS
Header set Access-Control-Allow-Origin "https://xxxx.altervista.org"
</Directory>