Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Apache: Users

How limit directives at htaccess file

 

 

Apache users RSS feed   Index | Next | Previous | View Threaded


apacheml at fuckaround

Aug 6, 2013, 11:54 AM

Post #1 of 4 (38 views)
Permalink
How limit directives at htaccess file

Hi all, I'm study apache and I don't understand some things about htaccess.

Reading, the advice is: never permit htaccess to users.

So, can I enable htaccess but only for personalize something like this?

ErrorDocument 400 /errors/badrequest.html
ErrorDocument 401 /errors/authreqd.html
ErrorDocument 403 /errors/forbid.html
ErrorDocument 404 /errors/notfound.html
ErrorDocument 500 /errors/serverr.html

and obviously deny all other directives?

so an user with own htaccess file, can only personalize that directives.

Any idea?

Thanks for replies :-)

Pol


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe [at] httpd
For additional commands, e-mail: users-help [at] httpd


ben at reser

Aug 6, 2013, 12:57 PM

Post #2 of 4 (34 views)
Permalink
Re: How limit directives at htaccess file [In reply to]

On Tue, Aug 6, 2013 at 11:54 AM, Pol Hallen <apacheml [at] fuckaround> wrote:
> Hi all, I'm study apache and I don't understand some things about htaccess.
>
> Reading, the advice is: never permit htaccess to users.
>
> So, can I enable htaccess but only for personalize something like this?
>
> ErrorDocument 400 /errors/badrequest.html
> ErrorDocument 401 /errors/authreqd.html
> ErrorDocument 403 /errors/forbid.html
> ErrorDocument 404 /errors/notfound.html
> ErrorDocument 500 /errors/serverr.html
>
> and obviously deny all other directives?
>
> so an user with own htaccess file, can only personalize that directives.

See AllowOverride:
http://httpd.apache.org/docs/current/mod/core.html#allowoverride

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe [at] httpd
For additional commands, e-mail: users-help [at] httpd


kremels at kreme

Aug 7, 2013, 5:28 AM

Post #3 of 4 (28 views)
Permalink
Re: How limit directives at htaccess file [In reply to]

On 06 Aug 2013, at 12:54 , Pol Hallen <apacheml [at] fuckaround> wrote:

> Hi all, I'm study apache and I don't understand some things about htaccess.
>
> Reading, the advice is: never permit htaccess to users.

That's terrible advice, or very outdated advice.

.htaccess is required, for example, for a working wordpress install. There is no reason, either, to not allow a user to change the Indexes setting. Disallowing them access to Limit means they can't password protect portions of their site.

> So, can I enable htaccess but only for personalize something like this?

You can restrict what is allowed in htaccess, yes.

> and obviously deny all other directives?

No obviously about it.

I do not know that AllowOverride will give the level of control you seem to think you need over your users, but it does provide some.

--
Hudd: 'I've just done this radio show where I never met any of the other
actors and I didn't understand what any of it was about' Moore: 'Ah, yes
I expect that's the thing I'm in.'


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe [at] httpd
For additional commands, e-mail: users-help [at] httpd


nick at webthing

Aug 7, 2013, 5:40 AM

Post #4 of 4 (28 views)
Permalink
Re: How limit directives at htaccess file [In reply to]

On 7 Aug 2013, at 13:28, LuKreme wrote:

> .htaccess is required, for example, for a working wordpress install.

Rubbish. htaccess is not required for anything. Its purpose is to enable
limited aspects of server admin to be devolved to unprivileged and
untrusted users.

> I do not know that AllowOverride will give the level of control you seem to think you need over your users, but it does provide some.

Yep. So the best advice is what Ben already posted. Read TFM, and
either figure something out or refine the question.

--
Nick Kew
---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe [at] httpd
For additional commands, e-mail: users-help [at] httpd

Apache users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.