# NXCart — deny direct web access to the admin component tree.
#
# Nothing here is meant to be fetched over HTTP: the admin app runs through
# /administrator/index.php and its assets live under /media/com_nxcart/. Denying
# direct access blocks recon of dependency versions (e.g. dompdf), the SQL
# schema, and the install manifest. Applies recursively to vendor/, sql/, etc.
#
# Apache only. On nginx add an equivalent server rule, e.g.:
#   location ^~ /administrator/components/com_nxcart/ { deny all; return 403; }

<IfModule mod_authz_core.c>
    Require all denied
</IfModule>
<IfModule !mod_authz_core.c>
    Order allow,deny
    Deny from all
</IfModule>
