<IfModule mod_headers.c>
  # Allow only specific origins dynamically
#   SetEnvIf Origin "^https://(clientkyc\.algoresponcetrading\.in|qap\.quickalgoplus\.co\.in)$" ALLOW_ORIGIN=$0

  Header always set Access-Control-Allow-Origin "%{ALLOW_ORIGIN}e" env=ALLOW_ORIGIN
  Header always set Access-Control-Allow-Methods "POST, GET, OPTIONS, PUT, DELETE"
  Header always set Access-Control-Allow-Headers "Origin, X-Requested-With, Content-Type, Accept, Authorization"

  Header always set X-Content-Type-Options "nosniff"
  Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
</IfModule>

# Always allow OPTIONS (preflight)
RewriteEngine On
RewriteCond %{REQUEST_METHOD} OPTIONS
RewriteRule ^(.*)$ $1 [R=200,L]

# Existing rewrite
RewriteCond %{REQUEST_URI} !^/public/
RewriteRule ^(.*)$ /public/$1 [L,QSA]


# <IfModule mod_rewrite.c>
#     <IfModule mod_headers.c>
#       Header always set Access-Control-Allow-Origin "https://clientkyc.algoresponcetrading.in, https://qap.quickalgoplus.co.in"
#     Header always set Access-Control-Allow-Methods "POST, GET, OPTIONS, PUT, DELETE"
#     Header always set Access-Control-Allow-Headers "Origin, X-Requested-With, Content-Type, Accept, Authorization"
    
#         Header set X-Content-Type-Options "nosniff"
#     Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' https:; style-src 'self' 'unsafe-inline' https:; img-src 'self' data: https:; font-src 'self' https: data:; connect-src 'self' https:; frame-ancestors 'none'; base-uri 'self'; form-action 'self';"
#         Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains; preload"
       
#     </IfModule>


#     <IfModule mod_negotiation.c>
#         Options -MultiViews -Indexes
#     </IfModule>

#     RewriteEngine On
#     RewriteCond %{REQUEST_URI} !^/public/
#     RewriteRule ^(.*)$ /public/$1 [L,QSA]


# </IfModule>

