.htaccess
From Free net encyclopedia
.htaccess (Hypertext Access) is the default name of Apache's directory-level configuration file. It provides the ability to customize configuration directives defined in the main configuration file. The configuration directives need to be in .htaccess context and the user needs appropriate permissions.
Contents |
Common usage
Custom Error Pages
ErrorDocument 404 my404page.html
- This code can be used to create any custom page. Certain pages are more complicated to modify - if you create a custom 403 Forbidden page, then a viewer will not see the custom page. Here is a way to get around this:
ErrorDocument 403 /all/my403page.html
- In the /all directory, you would need another .htaccess file, ie:
Order allow,deny Allow from all
- This would give access to Forbidden users to the /all directory, where the custom 403 page is kept in this example.
Password protection
Make the user enter a name and password before viewing a directory.
AuthUserFile /home/newuser/www/stash/.htpasswd AuthGroupFile /dev/null AuthName "Protected Directory" AuthType Basic <Limit GET POST> require user newuser </Limit>
Now run this command to create a new password for the user 'newuser'.
htpasswd /home/newuser/www/stash/.htpasswd newuser
Password unprotection
Unprotect a directory inside an otherwise protected structure:
Satisfy any
Enable SSI
AddType text/html .shtml AddHandler server-parsed .shtml Options Indexes FollowSymLinks Includes
Deny users by IP address
Order allow,deny Deny from 123.45.67.8 Deny from 123.123.7 Allow from all
- This would ban anyone with an IP address of 123.45.67.8 and would also ban anyone with an IP address starting in 123.123.7: for example, 123.123.74.42 would not gain access.
Change the default directory page
DirectoryIndex homepage.html
- Here, anyone visiting http://www.example.com/ would see the homepage.html page, rather than the default index.html.
Redirects
Redirect page1.html page2.html
- If someone was to visit http://www.example.com/page1.html, they would be sent to http://www.example.com/page2.html
Prevent hotlinking of images
The following .htaccess rules use mod rewrite.
From specific domains
RewriteEngine on RewriteCond %{HTTP_REFERER} ^http://([^/]+\.)?baddomain1\.com [NC,OR] RewriteCond %{HTTP_REFERER} ^http://([^/]+\.)?baddomain2\.com [NC,OR] RewriteCond %{HTTP_REFERER} ^http://([^/]+\.)?baddomain3\.com [NC] RewriteRule \.(gif|jpg)$ http://www.example.com/hotlink.gif [R,L]
Except from specific domains
RewriteEngine on RewriteCond %{HTTP_REFERER} !^$ RewriteCond %{HTTP_REFERER} !^http://(www\.)?example.com/.*$ [NC] RewriteRule \.(gif|jpg)$ http://www.example.com/hotlink.gif [R,L]
- Unless the image is displayed on example.com, browers would see the image hotlink.gif.
Directory rules
A .htaccess file controls the directory it is in, plus all subdirectories. However, by placing additional .htaccess files in the subdirectories, this can be overruled.
User permissions
The user permissions for .htaccess are controlled on server level with the AllowOverride directive which is documented in the Apache Server Documentation.
Other uses
Some web developers have modified .htaccess to perform custom tasks server-side before serving content to the browser. Here developer Shaun Inman shows it is possible to edit .htaccess to allow for Server Side Constants within CSS.
See also
External links
- Documentation for mod_rewrite, frequently used in .htaccess files
- Apache configuration directives allowed in .htaccess context
- Apache Documentation on the AllowOverride directive
- Apache Docs .htaccess Howto
- Ken Coar: Using .htaccess Files with Apache
- .htaccess The Guide
- .htaccess Generator - .htaccess and .htpasswd Generator to password-protect a directory. (Free tool)
- Clockwatchers .htaccess and .htpasswd Tool - generates .ht* files with many features.
- Beginner's .htaccess tutorial and Custom Error Page Generator - Beginner's .htaccess tutorial and Custom Error Page Generator in PHP (free)
- Shaun Shull: Using .htaccess to create search friendly URLs
- detailed .htaccess guide from MindSpring.comde:.htaccess