############################################
# Catálogo Fotomar — acceso al catálogo
############################################
Options -Indexes -ExecCGI -Includes -MultiViews
DirectoryIndex catalogo.html index.htm

# Por defecto: bloquear todo
<IfModule mod_authz_core.c>
  Require all denied
</IfModule>

# Permitir el catálogo HTML
<Files "index-old.htm">
  <IfModule mod_authz_core.c>
    Require all granted
  </IfModule>
</Files>

# Permitir index.htm si existe
<Files "index.htm">
  <IfModule mod_authz_core.c>
    Require all granted
  </IfModule>
</Files>

# Permitir imágenes en la carpeta img/
<FilesMatch "\.(jpg|jpeg|png|gif|webp|svg)$">
  <IfModule mod_authz_core.c>
    Require all granted
  </IfModule>
</FilesMatch>

# Permitir el Excel (opcional, quitar si no quieres que sea descargable)
<Files "detalle.xlsx">
  <IfModule mod_authz_core.c>
    Require all granted
  </IfModule>
</Files>

# Solo GET/HEAD
<LimitExcept GET HEAD>
  <IfModule mod_authz_core.c>
    Require all denied
  </IfModule>
</LimitExcept>

# Bloquear archivos ocultos (.htaccess, .env, etc.)
<FilesMatch "^\.">
  <IfModule mod_authz_core.c>
    Require all denied
  </IfModule>
</FilesMatch>

# Compatibilidad Apache 2.2
<IfModule !mod_authz_core.c>
  Order deny,allow
  Deny from all
  <Files "catalogo.html">
    Allow from all
  </Files>
  <Files "index.htm">
    Allow from all
  </Files>
  <FilesMatch "\.(jpg|jpeg|png|gif|webp|svg)$">
    Allow from all
  </FilesMatch>
  <Files "detalle.xlsx">
    Allow from all
  </Files>
  <LimitExcept GET HEAD>
    Deny from all
  </LimitExcept>
</IfModule>