mod_access.html revision db81e057b060e365d840d9a1d35a5797192efa81
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!-- Background white, links blue (unvisited), navy (visited), red (active) -->
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi BGCOLOR="#FFFFFF"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi TEXT="#000000"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi LINK="#0000FF"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi VLINK="#000080"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi ALINK="#FF0000"
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!--#include virtual="header.html" -->
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThis module is contained in the <code>mod_access.c</code> file, and
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiis compiled in by default. It provides access control based on client
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindihostname or IP address.
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<!--%plaintext <?INDEX {\tt allow} directive> -->
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<strong>Syntax:</strong> allow from <em>host host ...</em><br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe allow directive affects which hosts can access a given directory.
724365f7556fc4201fdb11766ebc6bd918523130sethg<dd>All hosts are allowed access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A (partial) domain-name
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>Hosts whose names match, or end in, this string are allowed access.
724365f7556fc4201fdb11766ebc6bd918523130sethg<dt>A full IP address
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>An IP address of a host allowed access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A partial IP address
724365f7556fc4201fdb11766ebc6bd918523130sethg<dd>The first 1 to 3 bytes of an IP address, for subnet restriction.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<blockquote><code>allow from .ncsa.uiuc.edu</code></blockquote>
724365f7556fc4201fdb11766ebc6bd918523130sethgAll hosts in the specified domain are allowed access.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiNote that this compares whole components; <code>bar.edu</code>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiSee also <A HREF="#deny">deny</A>, <A HREF="#order">order</A>, and
724365f7556fc4201fdb11766ebc6bd918523130sethg<a href="mod_browser.html#browsermatch">BrowserMatch</a>.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<a name="allowfromenv"><strong>Syntax:</strong> allow from env=<em>variablename</em></a><br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe allow from env directive controls access to a directory by the
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiexistence (or non-existence) of an environment variable.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<Directory /docroot>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiorder allow,deny
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiallow from env=let_me_in
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindideny from all
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi</Directory>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!--%plaintext <?INDEX {\tt deny} directive> -->
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Syntax:</strong> deny from <em>host host ...</em><br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe deny directive affects which hosts can access a given directory.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>all hosts are denied access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A (partial) domain-name
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>host whose name is, or ends in, this string are denied access.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A full IP address
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>An IP address of a host denied access
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>A partial IP address
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>The first 1 to 3 bytes of an IP address, for subnet restriction.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiAll hosts in the specified network are denied access.
724365f7556fc4201fdb11766ebc6bd918523130sethgNote that this compares whole components; <code>bar.edu</code>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiSee also <A HREF="#allow">allow</A> and <A HREF="#order">order</A>.
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<a name="denyfromenv"><strong>Syntax:</strong> deny from env=<em>variablename</em></a><br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe deny from env directive controls access to a directory by the
0eb822a1c0c2bea495647510b75f77f0e57633ebcindiexistence (or non-existence) of an environment variable.
0eb822a1c0c2bea495647510b75f77f0e57633ebcindi<Directory /docroot>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiorder deny,allow
12cc75c814f0c017004a9bbc96429911e008601bcindideny from env=go_away
12cc75c814f0c017004a9bbc96429911e008601bcindiallow from all
12cc75c814f0c017004a9bbc96429911e008601bcindi</Directory>
724365f7556fc4201fdb11766ebc6bd918523130sethg<!--%plaintext <?INDEX {\tt order} directive> -->
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<strong>Default:</strong> <code>order deny,allow</code><br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiThe order directive controls the order in which <A HREF="#allow">allow</A> and
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<A HREF="#deny">deny</A> directives are evaluated. <em>Ordering</em> is one
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>deny,allow
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>the deny directives are evaluated before the allow directives. (The
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiinitial state is OK.)
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>allow,deny
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>the allow directives are evaluated before the deny directives. (The
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiinitial state is FORBIDDEN.)
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dt>mutual-failure
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<dd>Only those hosts which appear on the allow list and do not appear
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindion the deny list are granted access. (The initial state is irrelevant.)
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiNote that in all cases every <code>allow</code> and <code>deny</code>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindistatement is evaluated, there is no "short-circuiting".
0eb822a1c0c2bea495647510b75f77f0e57633ebcindiorder deny,allow<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindideny from all<br>
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindiHosts in the ncsa.uiuc.edu domain are allowed access; all other hosts are
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindidenied access.
7aec1d6e253b21f9e9b7ef68b4d81ab9859b51fecindi<!--#include virtual="footer.html" -->