# Debians Standard-apache2.conf setzt AllowOverride None für /var/www/ - ohne diese Datei würden # sämtliche .htaccess-Regeln der App (HTTPS-Redirect, Security-Header, Deny-All auf lib/uploads/..., # Blockade von config.php/config.secret.php) stillschweigend ignoriert. Das wäre ein echtes # Sicherheitsloch (config.secret.php wäre sonst direkt per HTTP abrufbar). AllowOverride All