Access Control
Overview
Section titled “Overview”OLS provides IP-based access control at three levels:
- Server level — in
httpd_config.conf, applies to all requests - Virtual host level — in vhost config, applies to one site
- Context level — per URL path or directory
- .htaccess level — per directory, using the LiteHTTPD module
OLS Native Access Control
Section titled “OLS Native Access Control”Syntax
Section titled “Syntax”OLS uses accessControl blocks with allow and deny directives:
accessControl { allow 192.168.1.0/24, 10.0.0.0/8 deny ALL}The format is:
allow— comma-separated list of IPs, CIDR ranges, orALLdeny— comma-separated list of IPs, CIDR ranges, orALL
OLS evaluates deny rules first, then allow rules. A request is denied if it matches a deny rule and does not match any allow rule.
Server-Level Access Control
Section titled “Server-Level Access Control”In httpd_config.conf:
accessControl { allow ALL deny}Virtual Host Level
Section titled “Virtual Host Level”In the virtual host configuration file:
virtualhost example { ... accessControl { allow ALL deny 192.168.1.100, 10.0.0.50 }}Context Level
Section titled “Context Level”Restrict access to specific URL paths:
context /admin/ { location $VH_ROOT/admin/ allowBrowse 1
accessControl { allow 192.168.1.0/24 deny ALL }}WebAdmin Protection
Section titled “WebAdmin Protection”Restrict the WebAdmin GUI (port 7080) to trusted IPs:
listener admin { address *:7080 secure 1
accessControl { allow 192.168.1.0/24, 127.0.0.1 deny ALL }}.htaccess Access Control (LiteHTTPD)
Section titled “.htaccess Access Control (LiteHTTPD)”With the LiteHTTPD module installed, you can use Apache-compatible access control directives in .htaccess files.
Modern Syntax (Require)
Section titled “Modern Syntax (Require)”The Require directive is the modern Apache 2.4+ syntax:
# Allow specific IPRequire ip 192.168.1.0/24
# Allow allRequire all granted
# Deny allRequire all denied
# Multiple conditions (all must match)<RequireAll> Require ip 192.168.1.0/24 Require valid-user</RequireAll>
# Any condition matches<RequireAny> Require ip 10.0.0.0/8 Require ip 192.168.0.0/16</RequireAny>
# Negation<RequireAll> Require all granted <RequireNone> Require ip 192.168.1.100 </RequireNone></RequireAll>IPv6 Support
Section titled “IPv6 Support”The LiteHTTPD module supports full IPv6 CIDR notation:
Require ip 2001:db8::/32Require ip ::1Legacy Syntax (Order/Allow/Deny)
Section titled “Legacy Syntax (Order/Allow/Deny)”The older Apache 2.2 syntax is also supported:
# Deny by default, allow specific IPsOrder Deny,AllowDeny from allAllow from 192.168.1.0/24Allow from 10.0.0.0/8
# Allow by default, deny specific IPsOrder Allow,DenyAllow from allDeny from 192.168.1.100Restrict by File
Section titled “Restrict by File”Protect specific files:
# Block access to .env files<Files .env> Require all denied</Files>
# Block all dot-files<FilesMatch "^\."> Require all denied</FilesMatch>
# Protect wp-login.php<Files wp-login.php> Require ip 192.168.1.0/24</Files>Environment-Based Access
Section titled “Environment-Based Access”# Allow based on environment variableSetEnvIf User-Agent "MonitoringBot" allowed_botRequire env allowed_botCommon Patterns
Section titled “Common Patterns”Block Known Bad Actors
Section titled “Block Known Bad Actors”Create a deny list in the virtual host config:
accessControl { allow ALL deny 1.2.3.4, 5.6.7.0/24, 10.20.30.0/24}Allow Only Internal Networks
Section titled “Allow Only Internal Networks”# OLS nativeaccessControl { allow 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 127.0.0.1 deny ALL}
# .htaccess equivalentRequire ip 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 127.0.0.1Protect Admin Areas
Section titled “Protect Admin Areas”# In .htaccess for /wp-admin/<Files "*.php"> <RequireAny> Require ip 192.168.1.0/24 Require ip 10.0.0.0/8 </RequireAny></Files>
# Allow AJAX requests from all users<Files admin-ajax.php> Require all granted</Files>Country-Level Blocking
Section titled “Country-Level Blocking”OLS does not include built-in GeoIP. Use an external firewall (iptables, nftables, or fail2ban) or a CDN for country-level blocking.
Troubleshooting
Section titled “Troubleshooting”403 Forbidden but IP should be allowed:
- Check for conflicting rules at different levels (server > vhost > context)
- In
.htaccess, verify theOrderdirective matches your intent - Check for IPv6 vs IPv4 mismatches (client may connect via IPv6)
Access control not taking effect from .htaccess:
- Verify the LiteHTTPD module is loaded
- Check that
autoLoadHtaccessis enabled in the virtual host - Verify
.htaccessfile permissions are readable by the OLS user