Get the App
SLTechnology News&Howtos  ›  Servers  › 

How to understand deny and allow in Apache configuration file

Shulou Source: shulou.com Published: 2022-06-01 03:05:44 10月03日 Update

How to understand the deny and allow in the Apache configuration file, I believe that many inexperienced people are at a loss about this. Therefore, this paper summarizes the causes and solutions of the problem. Through this article, I hope you can solve this problem.

Summary of deny and allow in Apache configuration file. This article focuses on the execution order of deny and allow. Friends who need it can refer to it.

Today, when the company was configuring the local Apache environment of Zend, I found several sentences in the permission control in zend.conf, as follows:

The code is as follows:

SetHandler server-status

Order deny,allow

Deny from all

Allow from 127.0.0.1

You need to configure VirtualHost when configuring virtual hosts.

The code is as follows:

ServerName backend

DocumentRoot "D:/Program Files/Zend/Apache2/htdocs/public"

SetEnv APPLICATION_ENV "development"

DirectoryIndex index.php

AllowOverride All

Order allow,deny

Allow from all

The difference between the two Order statements interests me, so how exactly is the order executed here? Previously associated with the concept of "short circuit", there are the same, but also different, the following with a few examples to analyze.

The code is as follows:

Order deny,allow

-(note that there is only one comma between deny and allow, and it can only be written this way. All other words are incorrect.)

Allow from all

Deny from 219.204.253.8

All can pass.

The code is as follows:

Order deny,allow

Deny from 219.204.253.8

Allow from all

-all can pass.

The code is as follows:

Order allow,deny

Deny from 219.204.253.8

Allow from all

Only 219.204.253.8 failed.

The code is as follows:

Order allow,deny

Allow from all

Deny from 219.204.253.8

Only 219.204.253.8 failed.

According to the Apache official website, the allow direction affects hosts that can pass through a server zone, which can request conditions through the host name (hostname), IP address, IP address range, or through other clients. On the contrary, deny,deny controls hosts that are not allowed by the server, and deny is identified by hostname (hostname), http://www.bbqmw.net/qm_bbqmbd/IP address and range, or environment variables. The role of the top-level Order is to make the rules. For example, in case 1 above, our Order checks the deny first and then the allow, then we can treat the following two sentences as a list. There is no natural order for these two sentences, that is, when we check the deny, we find that the host 219.204.253.8 meets the rejection condition, so we do the second step test, that is, the allow check, and we find that what the allow does is: allow from all It means that all sources can be approved. The key here is that all visitors are not killed with a stick and have to go through two steps of verification, so it can be found that all machines can be passed, consistent with the results.

After reading the above, have you mastered how to understand deny and allow in the Apache configuration file? If you want to learn more skills or want to know more about it, you are welcome to follow the industry information channel, thank you for reading!

Tags: Host configuration code can pass check file only address time problem order different content method more server condition environment scope control Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Apple Shulou Tech Info Linux Shulou Technology MariaDB