You can restrict access to specific folders on your mybox hosting by using .htaccess and .htpasswd files. When a user tries to access a protected directory, their browser will prompt them for a username and password before any content is loaded.
This is a reliable way to secure administrative areas, staging sites, or private files without modifying your website’s code.
Table of Contents
How it works
To set up protection, you must create two hidden files inside the folder you want to secure (e.g., a folder named /secret/):
- .htaccess: Contains the instructions telling the server to require a password.
- .htpasswd: Contains the encrypted usernames and passwords.
Note: These filenames must start with a dot (
.). In many FTP clients, files starting with a dot are hidden by default; ensure your client is set to “Show hidden files” to manage them.
1. Create the .htaccess file
Use a plain text editor (like Notepad or TextEdit) to create a file named .htaccess. Paste the following configuration:
Apache
AuthType Basic
AuthName "Restricted Area"
AuthUserFile /home/mybox-login/public_html/secret/.htpasswd
Require valid-user
- AuthName: The message displayed in the login prompt.
- AuthUserFile: The full system path to your password file.
2. Create the .htpasswd file
The .htpasswd file stores credentials in an encrypted format. You can generate these strings using several methods:
- Online Generators: Use a tool like htpasswd generator to create the encrypted line (e.g.,
user:y9L.kR5v2). - Windows: Use a utility like
passwd.exe. - Linux/Terminal: Run the command
htpasswd -c .htpasswd username.
An example .htpasswd file looks like this:
Plaintext
admin:usAyCVmx1ycqI
manager:beae.2fYYfCwM
Protecting a Specific File
If you want to protect only one specific file (e.g., config.php) instead of the whole folder, wrap the requirement in a <Files> block within your .htaccess:
Apache
AuthType Basic
AuthName "File Access Restricted"
AuthUserFile /home/mybox-login/public_html/secret/.htpasswd
<Files "config.php">
Require valid-user
</Files>
Practical Implications
- Path Accuracy: The
AuthUserFilepath must be absolute. If your.htpasswdis in the same folder as the.htaccess, you can often simply useAuthUserFile .htpasswd, but using the full path is more reliable. - Security: Never store sensitive passwords in plain text. Always use the encrypted strings generated by the tools mentioned above.
- Website Functionality: Avoid protecting folders required for the public-facing side of your site (like
/css/or/images/), as this may prevent your website from loading correctly for visitors. - Removal: To stop password protection, simply delete the
.htaccessfile or remove theAuthlines from it via FTP.
Summary
Using .htpasswd provides a straightforward infrastructure-level security layer for your mybox hosting. It is an effective “lock” for directories that should not be indexed by search engines or accessed by the general public.