Table of Contents
What is a .htaccess file
The original idea behind the .htaccess file, as its name suggests, was to control access to the directories of the folder in which it is located. Currently, it is mainly used to override parameters included by default in the server configuration, for example, PHP settings and to indicate the use of rules by web page scripts, the purpose of which will be, for example, to rewrite links into a readable and easy-to-remember form.
It should be remembered that the .htaccess file and the values contained in it work both for files in the directory in which it is located, but also for all files located in subsequent directories in the structure. This happens until another .htaccess file is found in a given directory located lower in the structure and revokes/changes the rules set in the current one above.
./
├── your-files/
├── domain.com/
│ ├── awstats/
│ ├── public_html/
│ ├── .htaccess (includes folders and directories in public_html)
│ ├── pictures/
│ ├── style/
│ └── files/
│ ├── .htaccess (overwrites the rules from the file located in public_html)
│ ├── directory1/
│ └── directory2/ Why a period at the beginning of a file name?
In Linux systems, which are the basis of most servers running on the Internet, a dot at the beginning of a file or directory means that it is to be a hidden element. Therefore, very often when connecting via FTP to the server, the .htaccess file is not visible. Then you should make sure that in the settings of the file list and directories view in the FTP client application (e.g. FileZilla – information on how to configure the application can be found HERE) you have the option to show hidden items active.
What we use the .htaccess file for most often
The .htaccess file, as we mentioned at the beginning, is mainly used to change server configuration parameters and set link rewrite rules, so you can use it, for m.in example, in the following situations:
Custom error pages
In the event that the web server cannot fulfill the user’s request for various reasons, an error message is generated instead of the target page.
The list of errors reported by our system with their descriptions can be found under HTTP Errors.
With the help of the .htaccess file, we can define our own, independent of the system, pages explaining the situation.
To do this, we create a folder called /error-pages/ inside the public_html directory of our website.
In it, we place files with our own content displayed in the event of an error being generated, saving them as
<error_code.php> for example.
403.php for the No Access message.
We also create a .htaccess file inside the directory with our error pages with the following content:
Allow from all
Satisfy Any The next step will be to create a .htaccess file inside the public_html directory with the following syntax for each of the errors:
ErrorDocument <error_code> /error-pages/<error_code>.php for example.
ErrorDocument 401 /error-pages/401.php
ErrorDocument 403 /error-pages/403.php
ErrorDocument 404 /error-pages/404.php Now, after the server generates an exception, the page prepared by us will be displayed.
Website start page
The full URL consists of the domain name (1), the name of the individual folders (2) and the name of the target file (3), e.g.
www.mybox.com/file/test.zip
(1) (2) (3)
However, if the last part is not defined, the web server searches the specified directory in an attempt to find the file displayed by default in such a situation.
On our servers, the following values are automatically set as such names:
index.htm index.html index.cgi index.pl index.php index.php5 index.xhtml To set your own list or order of files as start pages, add the following directive to the .htaccess file:
DirectoryIndex <file names separated by a single space> For example.
DirectoryIndex index.html index.htm web.php index.php View a list of files
By default, listing files is blocked. If you want to display a list of files with all the contents of the current directory after calling a directory where there is no index.html or index.php file, you can add the following line in the .htaccess file:
Options +Indexes Change the address of pages
Sometimes it is necessary to change the address of some part of the website.
For example, a sales page will move from a www.company.mybox.com/commercial/ domain to www.commercial.company.mybox.com
In such a situation, Internet users using the old address should be redirected to the new one.
To do this, you need to create a .htaccess file in the old content folder with the following content:
Redirect <relative address of the old page> <address of the new page> for example.
Redirect /commercial/ http://www.commercial.company.mybox.com
An additional separate guide on this issue can be found HERE
Block resource hotlinking
The openness of the Internet also enables fraudulent activities, also in the field of creating websites. How many times has it happened that your photograph has been stolen and used without permission. In addition, the photo has not even been copied, but is downloaded from your website.
To prevent such situations, you can easily block the possibility of hotlinking – because this is the name for using resources from other servers without permission. Create a .htaccess file (or use an existing one) and include the following rule in it:
RewriteEngine On #this line should appear only once, if it already exists it can be omitted
RewriteCond %{HTTP_REFERER} !^$
RewriteCond %{HTTP_REFERER} !^http://(.+.)?firma.ro [NC]
RewriteRule ^pictures/.*.(jpe?g|gif|bmp|png)$ - [NC,F] Such a rule will not allow you to display on the page other than firma.pl image files from the /images/ directory. You can also add specific “friend” sites that we have allowed to use our resources. You need to duplicate the 3rd line and enter the appropriate domain of the “friendly” site there. At the same time, this script allows you to display images if someone enters its address directly into the browser.
If an image is hotlinked, our web server will return a 403 – No access error and the image will not be displayed.
Password protection of the directory
In this way, you can protect the directory from unauthorized access by specifying a list of users who will gain such access using the login and password.