. Without a buffer that redirect depends // entirely on php.ini's output_buffering: it is on for the dev stack but off // in production, where every protected page answered 200 with a half-rendered // body instead of sending the browser to the login form. session.php starts a // buffer for the same reason. if (ob_get_level() === 0) { ob_start(); } // Never render PHP notices/warnings into the page: they leak absolute server // paths to anonymous visitors and corrupt the markup. Errors still reach the // server log. This mirrors the policy db_auth.php already applies to the JSON // API routes, and keeps the app safe even where php.ini has display_errors on. ini_set('display_errors', '0'); ini_set('log_errors', '1'); // Security headers — emitted before any HTML output. header('X-Content-Type-Options: nosniff'); header('X-Frame-Options: SAMEORIGIN'); header('Referrer-Policy: strict-origin-when-cross-origin'); ?> BRN WMS