Turning Off Apache Basic Authentication For A Single Directory

11th September 2013 - 3 minutes read time

When setting up staging sites or similar I often add a simple Apache authentication check in order to stop everyone from viewing the site. This is also useful in stopping search engine spiders from accessing a site with testing content on it, which generally causes trouble. It isn't amazingly secure, but it keeps almost everyone out.

Setting up a basic Apache password check isn't difficult and all that is needed is a few lines of Apache configuration. This can be placed in a .htaccess file in the web directory or within the server configuration. The following configuration sets up a very simple authentication barrier.

  1. AuthName "Restricted Area"
  2. AuthType Basic
  3. AuthUserFile /var/www/passwords/.htpasswd
  4. AuthGroupFile /dev/null
  5. Require valid-user

The .htpasswd file in the above example is where your user information is stored, so it's generally a good idea to keep it outside your webroot. The .htpasswd file can be edited by hand, but the easiest way of adding passwords is to use the htpasswd command, this will prompt for a password.

htpasswd .htpasswd <username>

With all of that set up you might find the need to allow access to a certain directory. This might be in order to test incomming API connections to the server, which would otherwise be blocked. To allow access to a single directory you need to create an additional .htaccess file and add the Satify Any configuration option. This will tell Apache to allow any user to access the directory, therefore bypassing the password control.

Satisfy Any

You don't need to use a .htaccess file in order to control directory access in this way. The whole thing can be controlled from the main Apache web configuration, or via the virtual host configuration. Within the Apache configuration file the following config might be used to restrict access to a site within the directory /var/www/protected.

  1. <Directory /var/www/protected/>
  2. AuthName "Restricted Area"
  3. AuthType Basic
  4. AuthUserFile /var/www/passwords/.htpasswd
  5. AuthGroupFile /dev/null
  6. Require valid-user
  7. </Directory>

A single directory can be unprotected by adding an additional Directory declaration and including the Satisfy Any option like this.

  1. <Directory /var/www/protected/unprotected>
  2. Satisfy Any
  3. </Directory>

I should mention that this is basic authentication and is therefore not entirely safe, but it does a pretty good job in stopping most users and servers from accessing a website. There are no sophisticated brute force checking mechanisms or password encryption technologies in use. Also, if you aren't using SSL on the server the username and password can be intercepted and extracted.

Add new comment

The content of this field is kept private and will not be shown publicly.