Fonts and JSON fetched by sister sites need CORS headers (Security Headers and CORS), and nothing uploaded to /assets/ may run:
# Needs: mod_setenvif, mod_headers, mod_mime; AllowOverride FileInfo
AddType application/json .map
AddCharset utf-8 .css .js .mjs .json .map .svg
SetEnvIf Origin "^(https://(www|shop|blog)\.example\.com)$" CORS_ORIGIN=$1
Header set Access-Control-Allow-Origin "%{CORS_ORIGIN}e" env=CORS_ORIGIN
Header merge Vary "Origin"
<FilesMatch "\.(pdf|zip|csv|xlsx)$">
Header set Content-Disposition "attachment"
</FilesMatch>
<FilesMatch "\.(php\d?|phtml|phar|pl|py|cgi|sh)$">
SetHandler default-handler
ForceType text/plain
</FilesMatch>Line 2 fills a gap in Ubuntu 225 's mime.types (MIME Types). The header takes one origin, not a list, so lines 4 and 5 echo an allowed one back; line 6 warns caches. Lines 7 to 9 save files under their real type, and lines 10 to 13 send scripts as text:
/assets/fonts/inter.woff2 shop font/woff2 ACAO: https://shop.example.com Vary: Origin /assets/fonts/inter.woff2 evil font/woff2 Vary: Origin /assets/app.js.map - application/json; charset=utf-8 Vary: Origin /assets/files/prices.pdf - application/pdf Vary: Origin CD: attachment /assets/files/shell.php - text/plain body: <?php echo "ran";