Skip to content

Known Differences

These are behavioral changes introduced when you add LiteHTTPD to a stock OLS installation.

Stock OLSLiteHTTPD
Request to .htaccessServes file (200) or file not found (404)403 Forbidden
Request to .htpasswdSame403 Forbidden

LiteHTTPD enforces Apache’s default <Files ".ht*"> Require all denied</Files> behavior. Stock OLS has no such protection — .htaccess files may be publicly readable.

Stock OLSLiteHTTPD
Encoded ../ (e.g., %2e%2e/)400 or 404 (engine-dependent)403 Forbidden

LiteHTTPD adds defense-in-depth path traversal detection for percent-encoded bypass attempts.

Stock OLS ignores most .htaccess directives. After adding LiteHTTPD, all 80 supported directives become active. If your existing .htaccess files contain rules that were previously inert, they now take effect:

  • Require all denied → blocks access (403)
  • Header set → adds response headers
  • FilesMatch → enforces access control
  • AuthType Basic → requires authentication (401)

Review your .htaccess files before deploying LiteHTTPD in production.

Stock OLSLiteHTTPD (Full)LiteHTTPD (Thin)
Directory without index file404403 (with patch 0004)404 (unchanged)

Stock OLS returns 404 for directories without an index file. With LiteHTTPD Full (patch 0004), Options -Indexes returns 403, matching Apache behavior.

Options +ExecCGI in .htaccess is silently ignored by LiteHTTPD, regardless of edition. Apache allows this if AllowOverride Options is set. This is a deliberate security restriction.


The following features work identically to Apache:

  • All 80 supported directives
  • Directive merging across directory levels
  • AllowOverride category filtering
  • If/ElseIf/Else conditional expression evaluation
  • FilesMatch regex matching
  • RequireAny/RequireAll authorization logic
ApacheLiteHTTPD
X-Custom-Header: valuex-custom-header: value

OLS lowercases response header names. This is valid per HTTP/1.1 (RFC 7230) and required by HTTP/2. No functional impact.

AddHandler, SetHandler, RemoveHandler, and Action are parsed but do not change request handling. OLS uses scriptHandler in vhost config for handler mapping.

# Not supported
<If "%{REQUEST_URI} =~ /^\/api\//">
RewriteRule ^api/(.*)$ /handler.php?path=$1 [L]
</If>

Rewrite directives inside <If> blocks are logged and skipped. Place rewrite rules at the top level of .htaccess.

Multiple Header append directives for the same header name may only retain the last value in some OLS configurations. Use Header set with the complete value instead.

ErrorDocument with Local File Path (5xx Errors)

Section titled “ErrorDocument with Local File Path (5xx Errors)”

For ErrorDocument 404, LiteHTTPD handles local file paths correctly (the most common use case). However, for 5xx errors from PHP/backend, ErrorDocument 500 /error.html cannot fully replace the response body because OLS commits Content-Length before the module hook fires. Use an external URL redirect instead:

# Works for all status codes:
ErrorDocument 500 https://example.com/error.html
# Works for 404 (pre-checked at URI_MAP):
ErrorDocument 404 /error.html
# May not replace body for 5xx (use URL redirect instead):
ErrorDocument 500 /error.html

Options FollowSymLinks and Options MultiViews are passed to OLS’s engine, but OLS may not honor them identically to Apache. Test these if your site relies on them.


Stock OLS returns 404 for directories without an index file (not 200 with listing like Apache). With Patch 0004 and Options -Indexes, LiteHTTPD returns 403 matching Apache behavior.

Apache typically uses PHP-FPM (FastCGI), while OLS uses lsphp (LSAPI). The LSAPI protocol is more efficient but has different process management. See PHP Tuning for configuration.

If OLS’s native autoLoadHtaccess is enabled alongside LiteHTTPD, directives that both systems understand (ErrorDocument, Options) may be processed twice. Disable autoLoadHtaccess in your vhost config when using LiteHTTPD:

autoLoadHtaccess 0

LiteHTTPD-Thin (the .so module running on stock OLS without patches) has the following additional limitations compared to the Full edition:

FeatureFull EditionThin Edition
RewriteRule executionExecuted by patched OLS engineParsed but not executed; falls back to OLS native RewriteFile processing
php_value / php_flagPassed to lsphp via LSIAPIParsed but cannot be passed to lsphp (no PHPConfig patch)
Options -Indexes (403)Returns 403 (with Patch 0004)Returns 404 (stock OLS behavior)
readApacheConfAuto-converts Apache config at startupNot available

All other directives (Header, Require, FilesMatch, Auth, Expires, SetEnv, If/ElseIf/Else, etc.) work identically in both editions.