Protected Directories¶
Protects individual directories of a website — or the whole website — with a browser username and password prompt (HTTP Basic Auth). Typical for staging environments, internal areas, or a site that is not meant to be public yet.
Not a replacement for signing in to the application
The prompt protects access to files, not the application behind them. Whoever knows the password sees everything below it. User roles inside an application remain that application's own concern.
Setting up protection¶
- Navigate to Protected Directories
- Choose Add
- Select the website
- Enter the path — relative to the document root
- Give it a realm — the text the browser shows in the login prompt
- Add at least one user with a password
| Field | Meaning |
|---|---|
| Website | The website the directory belongs to |
| Path | Relative to the document root, e.g. internal or beta/preview |
| Realm | The text shown in the browser's login prompt |
| Users | One or more username and password pairs |
Protecting the whole website¶
Enter / as the path. Protection then covers the entire website including every
PHP request, not just static files.
Protecting a single directory¶
Enter the path without a leading slash, for example internal. That directory
and everything below it is protected.
Lifting protection temporarily¶
Every entry can be disabled with a switch instead of being deleted. Users and passwords are kept and protection can be switched back on at any time. Useful when a staging environment needs to be public for a while.
How it works underneath¶
The panel writes a password file under /etc/nginx/htpasswd.d on the server and
includes it through an nginx snippet. Passwords are stored hashed, not in clear
text.
Every change is validated against the nginx configuration before it is applied. If validation fails the previous state is restored, so a bad entry cannot take the web server down.
Passwords cannot be read back
A password cannot be displayed again once set. If it is lost, recreate the user with a new one.
Permission¶
Protected directories are a package permission. It is called Password Protection in the package editor and is enabled by default.
Without it the menu entry is hidden from the customer; as an administrator you can still set up protection for any website.
See Packages for managing permissions.
Common cases¶
No prompt appears. Check that the entry is enabled and that the path really exists. A path that does not exist produces no prompt.
The prompt appears but no password is accepted. Recreate the user. Passwords cannot be read back, only replaced.
The whole site is protected although only a subdirectory was meant. The path
was entered as /. Remove the entry and recreate it with the intended
subdirectory.