# Basic hardening + caching Options -Indexes Header set X-Content-Type-Options "nosniff" Header set X-Frame-Options "SAMEORIGIN" Header set Referrer-Policy "strict-origin-when-cross-origin" # Cache static assets ExpiresActive On ExpiresByType text/css "access plus 7 days" ExpiresByType application/javascript "access plus 7 days" ExpiresByType image/svg+xml "access plus 30 days" ExpiresByType image/png "access plus 30 days"