Directory Directives
<Directory> blocks let you set rules -- what's allowed, what's blocked, whether .htaccess files are honored -- for a specific folder on disk, rather than for a whole site.In this page:
The <Directory> Block
A <Directory "/path">...</Directory> block groups directives that apply only to that filesystem path (and, by default, everything inside it). It's most often used inside a <VirtualHost> to configure the site's own DocumentRoot, but it can appear anywhere in the main config too.
Require: Controlling Access
Modern Apache (2.4+) controls access with the Require directive: Require all granted allows everyone, Require all denied blocks everyone, and more specific forms like Require ip 192.168.1.0/24 or Require valid-user (combined with authentication) restrict access further. This replaced the older Order/Allow/Deny syntax from Apache 2.2.
Options: What a Directory Is Allowed to Do
The Options directive controls server behaviors for that directory. Indexes lets Apache generate an automatic file listing when there's no index file; FollowSymLinks lets it follow symbolic links; ExecCGI allows CGI scripts to run there. Prefixing an option with - or + toggles it individually, e.g. Options -Indexes disables just directory listings without touching the rest.
Options Indexes on a directory with no index file exposes every filename inside it to anyone who requests the folder -- fine for a public downloads folder, a real problem for anything containing config or backup files.AllowOverride: Enabling .htaccess
AllowOverride decides whether a .htaccess file inside that directory is even read. AllowOverride None (the modern secure default) ignores any .htaccess files entirely for performance and security. AllowOverride All lets .htaccess override anything the main config allows -- necessary for shared hosting where users can't edit the main config themselves, but discussed in more detail in the next lesson.
Nesting and Specificity
You can have multiple <Directory> blocks, including one nested inside another path. Apache applies them from the most general path to the most specific, so a <Directory "/var/www/site/private"> block's settings are layered on top of (and can override) a broader <Directory "/var/www/site"> block.
Example: Locking down a directory
<Directory "/var/www/example.com/public">
Options -Indexes +FollowSymLinks
AllowOverride None
Require all granted
</Directory>
<Directory "/var/www/example.com/public/admin">
Require ip 192.168.1.0/24
</Directory>
{# Flagged by hand after confirming a runner can't handle this example
(a shell command / go.mod file stored as a TopicExample, a language
feature the configured runner version doesn't support, or output
that blows a runner's sandbox limit) -- see TopicExample.norun.
Never render the run button for these, regardless of language,
since it would just fail at execute_code (or worse, hang the
Judge0 queue on a submission that can never finish cleanly). #}
- Leaving
Options Indexesenabled on a directory that was never meant to be browsed, accidentally listing every file inside it to the public. - Setting
AllowOverride Alleverywhere out of habit, whenAllowOverride Noneplus config in the main VirtualHost is faster and just as flexible for anything you control yourself. - Confusing the modern
Requiresyntax with the old Apache 2.2Order allow,deny/Allow fromsyntax -- mixing the two together doesn't work as expected on 2.4+.
Chapter Quiz — Complete all 4 topics to unlock
0/4 topics done
Complete these topics first: