# API Protection - Development Mode # للإنتاج: فعّل الحماية الكاملة # Allow all methods during development Require all granted # CORS Headers Header set Access-Control-Allow-Origin "*" Header set Access-Control-Allow-Methods "POST, GET, OPTIONS" Header set Access-Control-Allow-Headers "Content-Type, X-Requested-With" Header set Content-Type "application/json; charset=utf-8" # Rate Limiting (معطل للتطوير) # # SetOutputFilter RATE_LIMIT # SetEnv rate-limit 400 # # AJAX Check (معطل للتطوير - فعّله للإنتاج) # # RewriteEngine On # RewriteCond %{HTTP:X-Requested-With} !^XMLHttpRequest$ # RewriteRule .* - [F,L] # # Security Headers Header set X-Content-Type-Options "nosniff" Header set X-Frame-Options "SAMEORIGIN"