# API Protection - Development Mode
# للإنتاج: فعّل الحماية الكاملة
# Allow all methods during development
Require all granted
# CORS Headers
Header set Access-Control-Allow-Origin "*"
Header set Access-Control-Allow-Methods "POST, GET, OPTIONS"
Header set Access-Control-Allow-Headers "Content-Type, X-Requested-With"
Header set Content-Type "application/json; charset=utf-8"
# Rate Limiting (معطل للتطوير)
#
# SetOutputFilter RATE_LIMIT
# SetEnv rate-limit 400
#
# AJAX Check (معطل للتطوير - فعّله للإنتاج)
#
# RewriteEngine On
# RewriteCond %{HTTP:X-Requested-With} !^XMLHttpRequest$
# RewriteRule .* - [F,L]
#
# Security Headers
Header set X-Content-Type-Options "nosniff"
Header set X-Frame-Options "SAMEORIGIN"