Protected Directories¶
Protects a directory of your website — or the whole website — with a browser password prompt. Meant for staging pages, internal areas, or content that is not supposed to be public yet.
Setting up protection¶
- Navigate to Protected Directories
- Choose Add
- Select the website
- Enter the path — relative to your website's main directory
- Give it a realm — the text shown in the browser's login prompt
- Set a username and password
| Field | Example |
|---|---|
| Path | internal protects your-domain.com/internal |
Path / |
protects the entire website |
| Realm | Internal area |
You can add several users for the same directory.
Lifting protection temporarily¶
Instead of deleting the entry you can disable it. Users and passwords are kept and protection can be switched back on at any time.
Forgotten password¶
Passwords cannot be displayed — they are stored encrypted. Simply recreate the user with a new password.
What the protection does — and does not¶
It prevents access to files. Whoever knows the password sees everything below it.
For an application with its own user roles — WordPress, for instance — that application's own login remains in charge. Directory protection is an extra hurdle in front of it, not a replacement.
Whole website rather than a single folder
If a staging site should not be public at all, protect it with the path /.
The prompt then also covers PHP pages, not just images and files.