- mailer.php: re-enable TLS certificate verification for CyberMail API
calls (was CURLOPT_SSL_VERIFYPEER => false, exposing outbound mail
traffic to MITM).
- .htaccess / api/.htaccess: block direct HTTP access to .git/, db/,
and api/config.php via mod_rewrite [F] rules. Confirmed live that
/.git/config, /.git/logs/HEAD, and /db/schema.sql were all directly
downloadable (200 OK with real content) - .git exposure leaks the
repo's embedded GitHub token and full history; schema.sql leaks the
DB layout. Also drops the dead "/setup -> setup_password.php" rewrite,
since that file was already deleted from production.
- index.php: remove the 'download' route, which required a
api/download.php that has never existed in this repo - confirmed
live that GET /api/download returns a fatal 500.
- functions.php / upload.php / testimonials.php: extract the
duplicated image-upload validation/move logic (MIME check, size
check, UUID rename, move_uploaded_file) into one handleImageUpload()
helper used by both upload endpoints.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>