In some situations, you may want to provide FTP access to a user without allowing them to upload, modify, or delete files. This can be useful when granting access for auditing, troubleshooting, or viewing website content.
You can create a read-only FTP account by configuring permissions using a .ftpaccess file.
Table of Contents
Before You Begin
First, create the FTP account and assign it access to the desired directory.
Once the account has been created, connect to the server using FTP and navigate to the directory assigned to that FTP user.
Step 1: Create the .ftpaccess File
Inside the directory assigned to the FTP account, create a file named:
.ftpaccess Note: The filename begins with a dot (
.).
Step 2: Add Read-Only Rules
Insert the following configuration into the file:
<Limit CWD PWD DIRS READ>
AllowUser ftp_username
</Limit>
<Limit ALL>
DenyUser ftp_username
</Limit>
HideFiles "(\.ftpaccess)" Replace:
ftp_username with the actual FTP username.
How the Configuration Works
Allow Read Operations
<Limit CWD PWD DIRS READ>
AllowUser ftp_username
</Limit> This rule allows the user to:
- Browse directories
- View file listings
- Read and download files
Block Write Operations
<Limit ALL>
DenyUser ftp_username
</Limit> This prevents the user from performing actions such as:
- Uploading files
- Modifying files
- Renaming files
- Deleting files
- Creating directories
Hide the Configuration File
HideFiles "(\.ftpaccess)" This prevents the .ftpaccess file itself from appearing in directory listings.
Testing the Configuration
After saving the file:
- Connect using the FTP account.
- Verify that files can be viewed and downloaded.
- Attempt to upload or delete a file.
If the configuration is correct:
- Download operations will work normally.
- Upload, rename, and delete operations will be denied.
Important Notes
- The
.ftpaccessfile only affects the directory in which it is placed and its subdirectories. - Make sure the FTP account has been assigned to the correct directory before applying the rules.
- If multiple FTP users require read-only access, add separate
AllowUserentries for each account.
Summary
To create a read-only FTP account, place a .ftpaccess file in the directory assigned to the FTP user and configure rules that allow read operations while denying all write actions. This enables users to browse and download files without being able to modify the contents of the server.