RewriteEngine On
RewriteBase /
# Prevent Apache MultiViews from interfering with extensionless routes.
Options -MultiViews
# --- HTTPS and www (disable the HTTPS block if Infomaniak already forces TLS and this loops) ---
# www.peak2002.com, peak2002.ch and www.peak2002.ch all go to the main domain.
RewriteCond %{HTTP_HOST} ^www\.peak2002\.com$ [NC,OR]
RewriteCond %{HTTP_HOST} ^(www\.)?peak2002\.ch$ [NC]
RewriteRule ^ https://peak2002.com%{REQUEST_URI} [L,R=301]
RewriteCond %{HTTPS} !=on
RewriteCond %{HTTP:X-Forwarded-Proto} !https
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
# Block private / non-site paths even if they are uploaded by mistake.
RewriteRule ^admin(/|$) - [F,L]
RewriteRule ^data(/|$) - [F,L]
RewriteRule ^supabase(/|$) - [F,L]
RewriteRule ^scripts(/|$) - [F,L]
RewriteRule ^theme(/|$) - [F,L]
RewriteRule ^Claude.outputs(/|$) - [F,L]
RewriteRule ^images/tested.in.the.alps.images(/|$) - [F,L]
# --- Old URLs → launch URLs (301). Do this before the generic .html strip. ---
RewriteRule ^index\.html$ / [R=301,L]
RewriteRule ^product/?$ /skis [R=301,L]
RewriteRule ^product\.html$ /skis [R=301,L]
RewriteRule ^webshop/?$ /skis [R=301,L]
RewriteRule ^webshop\.html$ /skis [R=301,L]
RewriteRule ^compare/?$ /skis [R=301,L]
RewriteRule ^compare\.html$ /skis [R=301,L]
RewriteRule ^ski-finder/?$ /skis [R=301,L]
RewriteRule ^ski-finder\.html$ /skis [R=301,L]
RewriteRule ^product-piste/?$ /piste [R=301,L]
RewriteRule ^product-piste\.html$ /piste [R=301,L]
RewriteRule ^product-p-25/?$ /piste [R=301,L]
RewriteRule ^product-p-25\.html$ /piste [R=301,L]
RewriteRule ^product-all-mountain/?$ /all-mountain [R=301,L]
RewriteRule ^product-all-mountain\.html$ /all-mountain [R=301,L]
RewriteRule ^product-f-25/?$ /all-mountain [R=301,L]
RewriteRule ^product-f-25\.html$ /all-mountain [R=301,L]
RewriteRule ^product-freeride/?$ /freeride [R=301,L]
RewriteRule ^product-freeride\.html$ /freeride [R=301,L]
RewriteRule ^product-x-25/?$ /freeride [R=301,L]
RewriteRule ^product-x-25\.html$ /freeride [R=301,L]
RewriteRule ^product-touring/?$ /touring [R=301,L]
RewriteRule ^product-touring\.html$ /touring [R=301,L]
RewriteRule ^product-t-25/?$ /touring [R=301,L]
RewriteRule ^product-t-25\.html$ /touring [R=301,L]
RewriteRule ^ski-technology/?$ /technology [R=301,L]
RewriteRule ^ski-technology\.html$ /technology [R=301,L]
RewriteRule ^behind-the-scenes/?$ /technology [R=301,L]
RewriteRule ^behind-the-scenes\.html$ /technology [R=301,L]
RewriteRule ^team/?$ /about [R=301,L]
RewriteRule ^team\.html$ /about [R=301,L]
RewriteRule ^stories/?$ /about [R=301,L]
RewriteRule ^stories\.html$ /about [R=301,L]
RewriteRule ^faq/?$ /about#faq [R=301,NE,L]
RewriteRule ^faq\.html$ /about#faq [R=301,NE,L]
RewriteRule ^article/?$ /about [R=301,L]
RewriteRule ^article\.html$ /about [R=301,L]
RewriteRule ^blog-post/?$ /about [R=301,L]
RewriteRule ^blog-post\.html$ /about [R=301,L]
RewriteRule ^privacy-policy/?$ /privacy [R=301,L]
RewriteRule ^privacy-policy\.html$ /privacy [R=301,L]
RewriteRule ^terms-of-service/?$ /terms [R=301,L]
RewriteRule ^terms-of-service\.html$ /terms [R=301,L]
RewriteRule ^cookie-policy/?$ /cookies [R=301,L]
RewriteRule ^cookie-policy\.html$ /cookies [R=301,L]
# Trailing slash → canonical (except real directories).
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^(.+)/$ /$1 [R=301,L]
# Any remaining *.html → extensionless (technology.html → /technology).
RewriteCond %{THE_REQUEST} \s/+(.+?)\.html[\s?] [NC]
RewriteRule ^ /%1 [R=301,L]
# Serve existing files/directories as-is.
RewriteCond %{REQUEST_FILENAME} -f [OR]
RewriteCond %{REQUEST_FILENAME} -d
RewriteRule ^ - [L]
# Internally map extensionless URLs to corresponding .html files.
RewriteCond %{REQUEST_URI} !\.html$ [NC]
RewriteCond %{REQUEST_FILENAME}.html -f
RewriteRule ^(.+?)/?$ $1.html [L]
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set X-Frame-Options "DENY"
Header always set Permissions-Policy "camera=(), microphone=(), geolocation=()"
Header always set Content-Security-Policy "default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self'; connect-src 'self' blob:; frame-ancestors 'none'; base-uri 'self'; form-action 'self'"
Require all denied
Deny from all
# --- AI-readable copies (llms.txt convention) ---
# /llms.txt, /llms-full.txt and /.md are plain-text mirrors of the site for
# AI assistants. Serve them as UTF-8 text and keep the .md copies out of Google's
# index so they never compete with the real pages. Regenerate with
# scripts/build_llms.py after every copy change.
AddType text/markdown .md
AddCharset utf-8 .md .txt
Header set X-Robots-Tag "noindex, follow"
ErrorDocument 404 /404.html