# Images need to be publicly viewable (they're shown in the widget/dashboard),
# but nothing uploaded here should ever be allowed to EXECUTE as code —
# this blocks that, even if someone manages to upload a disguised .php file.
<FilesMatch "\.(php|php\d|phtml|pl|py|cgi|sh)$">
    Deny from all
</FilesMatch>

# Never let the browser guess a different type, and never run scripts from
# here (covers SVG logos uploaded before SVG uploads were disabled).
<IfModule mod_headers.c>
    Header set X-Content-Type-Options "nosniff"
    Header set Content-Security-Policy "default-src 'none'; img-src 'self'; style-src 'unsafe-inline'; sandbox"
</IfModule>
