mod_access.html revision db81e057b060e365d840d9a1d35a5797192efa81
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<HTML>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<HEAD>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<TITLE>Apache module mod_access</TITLE>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</HEAD>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!-- Background white, links blue (unvisited), navy (visited), red (active) -->
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<BODY
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi BGCOLOR="#FFFFFF"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi TEXT="#000000"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi LINK="#0000FF"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi VLINK="#000080"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi ALINK="#FF0000"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!--#include virtual="header.html" -->
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<H1 ALIGN="CENTER">Module mod_access</h1>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThis module is contained in the <code>mod_access.c</code> file, and
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiis compiled in by default. It provides access control based on client
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindihostname or IP address.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
12cc75c814f0c017004a9bbc96429911e008601bcindi
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<UL>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<li><A HREF="#allow">allow</A>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<li><A HREF="#allowfromenv">allow from env=</A>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<li><A HREF="#deny">deny</A>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<li><A HREF="#denyfromenv">deny from env=</A>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<li><A HREF="#order">order</A>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</UL>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<hr>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<h2><A name="allow">allow directive</A></h2>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<P>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<!--%plaintext &lt;?INDEX {\tt allow} directive&gt; -->
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<strong>Syntax:</strong> allow from <em>host host ...</em><br>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<Strong>Context:</strong> directory, .htaccess<br>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<Strong>Override:</strong> Limit<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Status:</strong> Base<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Module:</strong> mod_access
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe allow directive affects which hosts can access a given directory.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<em>Host</em> is one of the following:
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dl>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt><code>all</code>
724365f7556fc4201fdb11766ebc6bd918523130sethg<dd>All hosts are allowed access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A (partial) domain-name
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>Hosts whose names match, or end in, this string are allowed access.
724365f7556fc4201fdb11766ebc6bd918523130sethg<dt>A full IP address
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>An IP address of a host allowed access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A partial IP address
724365f7556fc4201fdb11766ebc6bd918523130sethg<dd>The first 1 to 3 bytes of an IP address, for subnet restriction.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</dl>
724365f7556fc4201fdb11766ebc6bd918523130sethg<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiExample:
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<blockquote><code>allow from .ncsa.uiuc.edu</code></blockquote>
724365f7556fc4201fdb11766ebc6bd918523130sethg<P>
724365f7556fc4201fdb11766ebc6bd918523130sethgAll hosts in the specified domain are allowed access.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiNote that this compares whole components; <code>bar.edu</code>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiwould not match <code>foobar.edu</code>.
724365f7556fc4201fdb11766ebc6bd918523130sethg</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiSee also <A HREF="#deny">deny</A>, <A HREF="#order">order</A>, and
724365f7556fc4201fdb11766ebc6bd918523130sethg<a href="mod_browser.html#browsermatch">BrowserMatch</a>.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
724365f7556fc4201fdb11766ebc6bd918523130sethg
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<a name="allowfromenv"><strong>Syntax:</strong> allow from env=<em>variablename</em></a><br>
724365f7556fc4201fdb11766ebc6bd918523130sethg<Strong>Context:</strong> directory, .htaccess<br>
724365f7556fc4201fdb11766ebc6bd918523130sethg<Strong>Override:</strong> Limit<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Status:</strong> Base<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Module:</strong> mod_access<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Compatibility:</strong> Apache 1.2 and above
724365f7556fc4201fdb11766ebc6bd918523130sethg</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe allow from env directive controls access to a directory by the
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiexistence (or non-existence) of an environment variable.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiExample:
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<blockquote><pre>
724365f7556fc4201fdb11766ebc6bd918523130sethgBrowserMatch ^KnockKnock/2.0 let_me_in
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi&lt;Directory /docroot&gt;
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiorder allow,deny
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiallow from env=let_me_in
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindideny from all
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi&lt;/Directory&gt;
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</pre></blockquote>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiSee also <A HREF="#denyfromenv">deny from env</A>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiand <A HREF="#order">order</A>.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<hr>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<h2><A name="deny">deny directive</A></h2>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!--%plaintext &lt;?INDEX {\tt deny} directive&gt; -->
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Syntax:</strong> deny from <em>host host ...</em><br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<Strong>Context:</strong> directory, .htaccess<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<Strong>Override:</strong> Limit<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Status:</strong> Base<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Module:</strong> mod_access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe deny directive affects which hosts can access a given directory.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<em>Host</em> is one of the following:
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dl>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt><code>all</code>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>all hosts are denied access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A (partial) domain-name
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>host whose name is, or ends in, this string are denied access.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A full IP address
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>An IP address of a host denied access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A partial IP address
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>The first 1 to 3 bytes of an IP address, for subnet restriction.
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi</dl>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiExample:
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<blockquote><code>deny from 16</code></blockquote>
724365f7556fc4201fdb11766ebc6bd918523130sethg<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiAll hosts in the specified network are denied access.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<P>
724365f7556fc4201fdb11766ebc6bd918523130sethgNote that this compares whole components; <code>bar.edu</code>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiwould not match <code>foobar.edu</code>.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiSee also <A HREF="#allow">allow</A> and <A HREF="#order">order</A>.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<a name="denyfromenv"><strong>Syntax:</strong> deny from env=<em>variablename</em></a><br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<Strong>Context:</strong> directory, .htaccess<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<Strong>Override:</strong> Limit<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Status:</strong> Base<br>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<strong>Module:</strong> mod_access<br>
724365f7556fc4201fdb11766ebc6bd918523130sethg<strong>Compatibility:</strong> Apache 1.2 and above
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe deny from env directive controls access to a directory by the
0eb822a1c0c2bea495647510b75f77f0e57633ebcindiexistence (or non-existence) of an environment variable.
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiExample:
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<blockquote><pre>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiBrowserMatch ^BadRobot/0.9 go_away
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi&lt;Directory /docroot&gt;
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiorder deny,allow
12cc75c814f0c017004a9bbc96429911e008601bcindideny from env=go_away
12cc75c814f0c017004a9bbc96429911e008601bcindiallow from all
12cc75c814f0c017004a9bbc96429911e008601bcindi&lt;/Directory&gt;
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</pre></blockquote>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiSee also <A HREF="#allowfromenv">allow from env</A>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindiand <A HREF="#order">order</A>.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<hr>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<h2><A name="order">order directive</A></h2>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
724365f7556fc4201fdb11766ebc6bd918523130sethg<!--%plaintext &lt;?INDEX {\tt order} directive&gt; -->
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<strong>Syntax:</strong> order <em>ordering</em><br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Default:</strong> <code>order deny,allow</code><br>
12cc75c814f0c017004a9bbc96429911e008601bcindi<strong>Context:</strong> directory, .htaccess<br>
12cc75c814f0c017004a9bbc96429911e008601bcindi<strong>Override:</strong> Limit<br>
12cc75c814f0c017004a9bbc96429911e008601bcindi<strong>Status:</strong> Base<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Module:</strong> mod_access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe order directive controls the order in which <A HREF="#allow">allow</A> and
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<A HREF="#deny">deny</A> directives are evaluated. <em>Ordering</em> is one
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiof
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dl>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>deny,allow
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>the deny directives are evaluated before the allow directives. (The
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiinitial state is OK.)
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>allow,deny
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>the allow directives are evaluated before the deny directives. (The
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiinitial state is FORBIDDEN.)
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>mutual-failure
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>Only those hosts which appear on the allow list and do not appear
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindion the deny list are granted access. (The initial state is irrelevant.)
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</dl>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiNote that in all cases every <code>allow</code> and <code>deny</code>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindistatement is evaluated, there is no &quot;short-circuiting&quot;.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<p>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiExample:
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<blockquote><code>
0eb822a1c0c2bea495647510b75f77f0e57633ebcindiorder deny,allow<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindideny from all<br>
12cc75c814f0c017004a9bbc96429911e008601bcindiallow from .ncsa.uiuc.edu<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</code></blockquote>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiHosts in the ncsa.uiuc.edu domain are allowed access; all other hosts are
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindidenied access.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</P>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!--#include virtual="footer.html" -->
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</BODY>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</HTML>
724365f7556fc4201fdb11766ebc6bd918523130sethg