Access Control
Access control directives restrict who can access your site or specific directories. LiteHTTPD supports both the legacy Order/Allow/Deny syntax and the modern Require syntax.
Directive Reference
Section titled “Directive Reference”| Directive | Syntax | Description |
|---|---|---|
Order | Order Allow,Deny or Order Deny,Allow | Set the evaluation order for Allow/Deny rules |
Allow from | Allow from ip|cidr|all | Allow access from specified addresses |
Deny from | Deny from ip|cidr|all | Deny access from specified addresses |
Require all granted | Require all granted | Allow access to everyone (modern syntax) |
Require all denied | Require all denied | Deny access to everyone (modern syntax) |
Require ip | Require ip ip|cidr [...] | Allow access from specified IPs or CIDR ranges |
Require not ip | Require not ip ip|cidr [...] | Deny access from specified IPs or CIDR ranges |
Require env | Require env VAR | Allow access when the named environment variable is set |
Examples
Section titled “Examples”Block Access to a Directory (Legacy Syntax)
Section titled “Block Access to a Directory (Legacy Syntax)”Order Deny,AllowDeny from allAllow from 192.168.1.0/24Allow from 10.0.0.0/8Block Access (Modern Syntax)
Section titled “Block Access (Modern Syntax)”Require all deniedAllow Only Specific IPs
Section titled “Allow Only Specific IPs”Require ip 203.0.113.50Require ip 2001:db8::/32Protect WordPress Admin
Section titled “Protect WordPress Admin”<Files "wp-login.php"> Order Deny,Allow Deny from all Allow from 203.0.113.50</Files>Block PHP Execution in Uploads
Section titled “Block PHP Execution in Uploads”# Place in wp-content/uploads/.htaccess<FilesMatch "\.php$"> Require all denied</FilesMatch>Conditional Access with Environment
Section titled “Conditional Access with Environment”SetEnvIf X-Forwarded-For "^10\." is_internalRequire env is_internal