RewriteEngine On RewriteBase / # Prevent Apache MultiViews from interfering with extensionless routes. Options -MultiViews # --- HTTPS and www (disable the HTTPS block if Infomaniak already forces TLS and this loops) --- # www.peak2002.com, peak2002.ch and www.peak2002.ch all go to the main domain. RewriteCond %{HTTP_HOST} ^www\.peak2002\.com$ [NC,OR] RewriteCond %{HTTP_HOST} ^(www\.)?peak2002\.ch$ [NC] RewriteRule ^ https://peak2002.com%{REQUEST_URI} [L,R=301] RewriteCond %{HTTPS} !=on RewriteCond %{HTTP:X-Forwarded-Proto} !https RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301] # Block private / non-site paths even if they are uploaded by mistake. RewriteRule ^admin(/|$) - [F,L] RewriteRule ^data(/|$) - [F,L] RewriteRule ^supabase(/|$) - [F,L] RewriteRule ^scripts(/|$) - [F,L] RewriteRule ^theme(/|$) - [F,L] RewriteRule ^Claude.outputs(/|$) - [F,L] RewriteRule ^images/tested.in.the.alps.images(/|$) - [F,L] # --- Old URLs → launch URLs (301). Do this before the generic .html strip. --- RewriteRule ^index\.html$ / [R=301,L] RewriteRule ^product/?$ /skis [R=301,L] RewriteRule ^product\.html$ /skis [R=301,L] RewriteRule ^webshop/?$ /skis [R=301,L] RewriteRule ^webshop\.html$ /skis [R=301,L] RewriteRule ^compare/?$ /skis [R=301,L] RewriteRule ^compare\.html$ /skis [R=301,L] RewriteRule ^ski-finder/?$ /skis [R=301,L] RewriteRule ^ski-finder\.html$ /skis [R=301,L] RewriteRule ^product-piste/?$ /piste [R=301,L] RewriteRule ^product-piste\.html$ /piste [R=301,L] RewriteRule ^product-p-25/?$ /piste [R=301,L] RewriteRule ^product-p-25\.html$ /piste [R=301,L] RewriteRule ^product-all-mountain/?$ /all-mountain [R=301,L] RewriteRule ^product-all-mountain\.html$ /all-mountain [R=301,L] RewriteRule ^product-f-25/?$ /all-mountain [R=301,L] RewriteRule ^product-f-25\.html$ /all-mountain [R=301,L] RewriteRule ^product-freeride/?$ /freeride [R=301,L] RewriteRule ^product-freeride\.html$ /freeride [R=301,L] RewriteRule ^product-x-25/?$ /freeride [R=301,L] RewriteRule ^product-x-25\.html$ /freeride [R=301,L] RewriteRule ^product-touring/?$ /touring [R=301,L] RewriteRule ^product-touring\.html$ /touring [R=301,L] RewriteRule ^product-t-25/?$ /touring [R=301,L] RewriteRule ^product-t-25\.html$ /touring [R=301,L] RewriteRule ^ski-technology/?$ /technology [R=301,L] RewriteRule ^ski-technology\.html$ /technology [R=301,L] RewriteRule ^behind-the-scenes/?$ /technology [R=301,L] RewriteRule ^behind-the-scenes\.html$ /technology [R=301,L] RewriteRule ^team/?$ /about [R=301,L] RewriteRule ^team\.html$ /about [R=301,L] RewriteRule ^stories/?$ /about [R=301,L] RewriteRule ^stories\.html$ /about [R=301,L] RewriteRule ^faq/?$ /about#faq [R=301,NE,L] RewriteRule ^faq\.html$ /about#faq [R=301,NE,L] RewriteRule ^article/?$ /about [R=301,L] RewriteRule ^article\.html$ /about [R=301,L] RewriteRule ^blog-post/?$ /about [R=301,L] RewriteRule ^blog-post\.html$ /about [R=301,L] RewriteRule ^privacy-policy/?$ /privacy [R=301,L] RewriteRule ^privacy-policy\.html$ /privacy [R=301,L] RewriteRule ^terms-of-service/?$ /terms [R=301,L] RewriteRule ^terms-of-service\.html$ /terms [R=301,L] RewriteRule ^cookie-policy/?$ /cookies [R=301,L] RewriteRule ^cookie-policy\.html$ /cookies [R=301,L] # Trailing slash → canonical (except real directories). RewriteCond %{REQUEST_FILENAME} !-d RewriteRule ^(.+)/$ /$1 [R=301,L] # Any remaining *.html → extensionless (technology.html → /technology). RewriteCond %{THE_REQUEST} \s/+(.+?)\.html[\s?] [NC] RewriteRule ^ /%1 [R=301,L] # Serve existing files/directories as-is. RewriteCond %{REQUEST_FILENAME} -f [OR] RewriteCond %{REQUEST_FILENAME} -d RewriteRule ^ - [L] # Internally map extensionless URLs to corresponding .html files. RewriteCond %{REQUEST_URI} !\.html$ [NC] RewriteCond %{REQUEST_FILENAME}.html -f RewriteRule ^(.+?)/?$ $1.html [L] Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" Header always set X-Content-Type-Options "nosniff" Header always set Referrer-Policy "strict-origin-when-cross-origin" Header always set X-Frame-Options "DENY" Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()" Header always set Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self'; connect-src 'self' blob:; frame-ancestors 'none'; base-uri 'self'; form-action 'self'" Require all denied Deny from all # --- AI-readable copies (llms.txt convention) --- # /llms.txt, /llms-full.txt and /.md are plain-text mirrors of the site for # AI assistants. Serve them as UTF-8 text and keep the .md copies out of Google's # index so they never compete with the real pages. Regenerate with # scripts/build_llms.py after every copy change. AddType text/markdown .md AddCharset utf-8 .md .txt Header set X-Robots-Tag "noindex, follow" ErrorDocument 404 /404.html