Skip to content

Protected Directories

Protects individual directories of a website — or the whole website — with a browser username and password prompt (HTTP Basic Auth). Typical for staging environments, internal areas, or a site that is not meant to be public yet.

Not a replacement for signing in to the application

The prompt protects access to files, not the application behind them. Whoever knows the password sees everything below it. User roles inside an application remain that application's own concern.


Setting up protection

  1. Navigate to Protected Directories
  2. Choose Add
  3. Select the website
  4. Enter the path — relative to the document root
  5. Give it a realm — the text the browser shows in the login prompt
  6. Add at least one user with a password
Field Meaning
Website The website the directory belongs to
Path Relative to the document root, e.g. internal or beta/preview
Realm The text shown in the browser's login prompt
Users One or more username and password pairs

Protecting the whole website

Enter / as the path. Protection then covers the entire website including every PHP request, not just static files.

Protecting a single directory

Enter the path without a leading slash, for example internal. That directory and everything below it is protected.


Lifting protection temporarily

Every entry can be disabled with a switch instead of being deleted. Users and passwords are kept and protection can be switched back on at any time. Useful when a staging environment needs to be public for a while.


How it works underneath

The panel writes a password file under /etc/nginx/htpasswd.d on the server and includes it through an nginx snippet. Passwords are stored hashed, not in clear text.

Every change is validated against the nginx configuration before it is applied. If validation fails the previous state is restored, so a bad entry cannot take the web server down.

Passwords cannot be read back

A password cannot be displayed again once set. If it is lost, recreate the user with a new one.


Permission

Protected directories are a package permission. It is called Password Protection in the package editor and is enabled by default.

Without it the menu entry is hidden from the customer; as an administrator you can still set up protection for any website.

See Packages for managing permissions.


Common cases

No prompt appears. Check that the entry is enabled and that the path really exists. A path that does not exist produces no prompt.

The prompt appears but no password is accepted. Recreate the user. Passwords cannot be read back, only replaced.

The whole site is protected although only a subdirectory was meant. The path was entered as /. Remove the entry and recreate it with the intended subdirectory.