Server Fault Asked by jkeesh on January 1, 2022

I have a site with a virtual directory structure like which is actually a .htaccess rewrite to I want to password protect the folder folder with .htaccess, and know how to do that with actual folders. But I don’t want to password protect the main site, and right now if I put the .htaccess file in the directory, I am protecting and I have also tried protecting

How can I protect only using .htaccess?

.htaccess contents of

<IfModule mod_rewrite.c>
RewriteEngine On

RewriteRule ^folder/(.*)$ /f/index.php?p=$1 [PT,L,QSA]
RewriteRule ^folder/*$ /f/index.php [L,QSA]

RewriteBase /
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]


.htaccess file I tried in This successfully protects the entire site when moved into the other .htaccess file, so I know the path is correct.

AuthName "Restricted Area" 
AuthType Basic 
AuthUserFile /home/myusername/.htpasswd 

One Answer

First of all you shouldn't be putting that configuration (the rewrite rules) in .htaccess files, you should be putting it in the main configuration file under a Directory section (assuming you have access to that file). The Apache docs explain why.

You should check that you have the correct AllowOverride settings. If it's all setup correctly, having the .htaccess file you specified sitting in the mysite/f folder should be enough to password protect it.

Answered by imoatama on January 1, 2022

