Directory Directives का उपयोग
<Directory> blocks आपको किसी specific folder के लिए rules -- क्या allowed है, क्या blocked है, क्या .htaccess files honor होती हैं -- set करने देते हैं, पूरी site के लिए नहीं।In this page:
The <Directory> Block
एक <Directory "/path">...</Directory> block उन directives को group करता है जो सिर्फ उस filesystem path पर (और, by default, इसके अंदर की हर चीज़ पर) apply होते हैं। यह सबसे ज़्यादा किसी <VirtualHost> के अंदर site की अपनी DocumentRoot configure करने के लिए इस्तेमाल होता है, लेकिन यह main config में कहीं भी आ सकता है।
Require: Access Control करना
Modern Apache (2.4+) access को Require directive से control करता है: Require all granted सबको allow करता है, Require all denied सबको block करता है, और Require ip 192.168.1.0/24 या Require valid-user (authentication के साथ combined) जैसे ज़्यादा specific forms access को और restrict करते हैं। इसने Apache 2.2 के पुराने Order/Allow/Deny syntax की जगह ली।
Options: Directory को क्या करने की Permission है
Options directive उस directory के लिए server behaviors control करता है। Indexes Apache को index file न होने पर एक automatic file listing generate करने देता है; FollowSymLinks इसे symbolic links follow करने देता है; ExecCGI वहाँ CGI scripts चलने देता है। किसी option के आगे - या + लगाना उसे individually toggle करता है, जैसे Options -Indexes बाकी को बिना छुए सिर्फ directory listings disable करता है।
Options Indexes किसी को भी उस folder की request करने पर अंदर की हर filename दिखा देता है -- एक public downloads folder के लिए ठीक है, लेकिन config या backup files वाली किसी भी चीज़ के लिए एक real problem है।AllowOverride: .htaccess Enable करना
AllowOverride decide करता है कि उस directory के अंदर की एक .htaccess file पढ़ी भी जाती है या नहीं। AllowOverride None (modern secure default) performance और security के लिए किसी भी .htaccess file को पूरी तरह ignore करता है। AllowOverride All .htaccess को main config की जो भी अनुमति हो उसे override करने देता है -- shared hosting के लिए ज़रूरी जहाँ users खुद main config edit नहीं कर सकते, जिसे अगले lesson में detail में discuss किया गया है।
Nesting और Specificity
आप एक path के अंदर nested दूसरे समेत कई <Directory> blocks रख सकते हैं। Apache इन्हें सबसे general path से सबसे specific तक apply करता है, इसलिए एक <Directory "/var/www/site/private"> block की settings एक ज़्यादा broad <Directory "/var/www/site"> block के ऊपर layer होती हैं (और उसे override कर सकती हैं)।
उदाहरण: Locking down a directory
<Directory "/var/www/example.com/public">
Options -Indexes +FollowSymLinks
AllowOverride None
Require all granted
</Directory>
<Directory "/var/www/example.com/public/admin">
Require ip 192.168.1.0/24
</Directory>
{# Flagged by hand after confirming a runner can't handle this example
(a shell command / go.mod file stored as a TopicExample, a language
feature the configured runner version doesn't support, or output
that blows a runner's sandbox limit) -- see TopicExample.norun.
Never render the run button for these, regardless of language,
since it would just fail at execute_code (or worse, hang the
Judge0 queue on a submission that can never finish cleanly). #}
- जिस directory को कभी browse होने के लिए नहीं बनाया गया उस पर
Options Indexeson छोड़ देना, गलती से इसके अंदर की हर file public को list करना। - आदत से हर जगह
AllowOverride Allset करना, जबAllowOverride Noneplus main VirtualHost में config उन चीज़ों के लिए तेज़ है और उतना ही flexible है जिन्हें आप खुद control करते हैं। - modern
Requiresyntax को पुराने Apache 2.2Order allow,deny/Allow fromsyntax से confuse करना -- दोनों को साथ mix करना 2.4+ पर उम्मीद के मुताबिक काम नहीं करता।
Chapter Quiz — Complete all 4 topics to unlock
0/4 topics done
Complete these topics first: