← Back to Apache Course | Chapter 4: Security | Lesson 1 of 4

Basic Auth जोड़ना

HTTP Basic Authentication किसी directory के आगे username/password की एक दीवार खड़ी करने का सबसे simple तरीका है -- page दिखाने से पहले browser अपना खुद का native login box popup करता है।

Basic Auth कैसे काम करता है

जब एक browser किसी protected resource की request करता है, Apache एक 401 Unauthorized status और एक WWW-Authenticate header से reply करता है। browser अपना built-in login prompt दिखाता है, फिर credentials के साथ request दोबारा भेजता है, एक Authorization header में base64-encoded (encrypted नहीं -- Basic Auth को network पर safe रहने के लिए हमेशा HTTPS के साथ pair होना चाहिए)।

Warning: Basic Auth credentials सिर्फ base64-encoded होते हैं, encrypted नहीं -- plain HTTP traffic intercept करने वाला कोई भी इन्हें trivially decode कर सकता है, इसलिए HTTPS के बिना Basic Auth कभी इस्तेमाल न करें।

एक Password File बनाना

Apache credentials को htpasswd से बनाई एक password file के against check करता है, जो DocumentRoot के बाहर रखी जाती है ताकि इसे कभी सीधे download न किया जा सके। sudo htpasswd -c /etc/apache2/.htpasswd alice पहले user के साथ एक नई file बनाता है (password के लिए prompt करते हुए); बाकी users के लिए -c drop करें ताकि file overwrite न हो।

Directives

एक <Directory> block (या .htaccess, अगर allowed हो) के अंदर: AuthType Basic Basic Auth select करता है, AuthName "Restricted Area" वह text set करता है जो browser के login prompt में दिखता है, AuthUserFile /etc/apache2/.htpasswd password file की ओर point करता है, और Require valid-user कहता है कि उस file में कोई भी username/password pair accepted है।

Specific Users तक Restrict करना

Require valid-user की जगह, Require user alice bob password file में सिर्फ उन दो specific usernames को accept करता है, भले ही इसमें दूसरे users exist करते हों -- useful जब एक shared .htpasswd file कई protected areas को different allowed users के साथ cover करती है।

उदाहरण: Password-protecting a directory

apacheconf
# Create the password file (first user)
# sudo htpasswd -c /etc/apache2/.htpasswd alice

<Directory "/var/www/example.com/admin">
    AuthType Basic
    AuthName "Restricted Area"
    AuthUserFile /etc/apache2/.htpasswd
    Require valid-user
</Directory>
{# Flagged by hand after confirming a runner can't handle this example (a shell command / go.mod file stored as a TopicExample, a language feature the configured runner version doesn't support, or output that blows a runner's sandbox limit) -- see TopicExample.norun. Never render the run button for these, regardless of language, since it would just fail at execute_code (or worse, hang the Judge0 queue on a submission that can never finish cleanly). #}

⚠️ This example can't run in the browser editor. Try it in your own local environment instead.

{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. .htpasswd file को public DocumentRoot के अंदर store करना, जहाँ एक misconfiguration किसी को इसे download करके offline crack करने दे सकती है।
  2. production में plain HTTP पर HTTP Basic Auth इस्तेमाल करना, network traffic observe कर पाने वाले किसी को भी credentials expose करते हुए।
  3. दूसरे user के लिए htpasswd को -c के साथ दोबारा चलाना, जो file overwrite कर देता है और पहला user जोड़ने की बजाय delete कर देता है।
🔒

Chapter Quiz — Complete all 4 topics to unlock

0/4 topics done

Complete these topics first:

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.