What is HTTP authentication?
HTTP authentication is a simple lock for a web page or folder. When a visitor opens it, the browser shows a small box that asks for a user name and password. It is like a door with a keypad.
Apache is a very common web server program. An .htaccess file is a small settings file you place in a folder. Apache reads it to learn the rules for that folder.
Turn it on
- Log in to your server over SSH, or use your file manager. If you use a control panel, look for a tool called Directory Privacy or Password Protect Directories. It does the same job with buttons.
- Create the password file with this command. Replace
johnwith the user name you want:
It asks for a password twice and saves it in scrambled form. Keep this file outside your public website folder.htpasswd -c /home/youruser/.htpasswd john - To add another user later, run the same command without
-c. The-cpart creates a new file and would erase the old one. - Open or create the
.htaccessfile in the folder you want to protect. - Add these lines:
AuthType Basic AuthName "Private area" AuthUserFile /home/youruser/.htpasswd Require valid-userAuthNameis the text shown in the login box.AuthUserFileis the full path of your password file. - Save the file.
- Open the folder in your browser. The login box should appear.
Turn it off
- Open the
.htaccessfile again. - Delete the four lines you added, or put a
#in front of each line. - Save the file.
- Reload the page. The box should be gone.
Warning: take a copy of your .htaccess file before you edit it. A typing mistake can make the whole site show an error.
If it does not work
- Check that the path in
AuthUserFileis right. - Check that the password file can be read by the web server.
- If you get a 500 error, look at the error log or remove the lines you added.
- Some servers do not allow
.htaccess. Ask Hostvento support.
Tip: Use HTTPS on the site. Basic authentication sends the password in a form that is easy to read on a plain HTTP connection.
Quick recap
- HTTP authentication asks for a user name and password.
- Create users with
htpasswd. - Add four lines to
.htaccessto turn it on. - Remove the lines to turn it off.
- Back up the file before editing.