Linux cesa-www-main 6.1.0-49-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.174-1 (2026-05-26) x86_64
Apache/2.4.68 (Debian)
Server IP : 10.218.0.2 & Your IP : 216.73.216.28
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
share /
doc /
apache2-doc /
manual /
tr /
mod /
Delete
Unzip
Name
Size
Permission
Date
Action
core.html
337.67
KB
-rw-r--r--
2026-06-12 05:08
directive-dict.html
20.46
KB
-rw-r--r--
2026-06-12 05:08
directives.html
58.19
KB
-rw-r--r--
2026-06-12 05:08
event.html
28.64
KB
-rw-r--r--
2026-06-12 05:08
index.html
24.98
KB
-rw-r--r--
2026-06-12 05:08
mod_access_compat.html
28.27
KB
-rw-r--r--
2026-06-12 05:08
mod_actions.html
12.61
KB
-rw-r--r--
2026-06-12 05:08
mod_alias.html
43.79
KB
-rw-r--r--
2026-06-12 05:08
mod_allowmethods.html
7.79
KB
-rw-r--r--
2026-06-12 05:08
mod_asis.html
8.65
KB
-rw-r--r--
2026-06-12 05:08
mod_auth_basic.html
19.39
KB
-rw-r--r--
2026-06-12 05:08
mod_auth_digest.html
20.06
KB
-rw-r--r--
2026-06-12 05:08
mod_auth_form.html
50.26
KB
-rw-r--r--
2026-06-12 05:08
mod_authn_anon.html
16.37
KB
-rw-r--r--
2026-06-12 05:08
mod_authn_core.html
16.45
KB
-rw-r--r--
2026-06-12 05:08
mod_authn_dbd.html
15.01
KB
-rw-r--r--
2026-06-12 05:08
mod_authn_dbm.html
12.48
KB
-rw-r--r--
2026-06-12 05:08
mod_authn_file.html
11.17
KB
-rw-r--r--
2026-06-12 05:08
mod_authn_socache.html
18.79
KB
-rw-r--r--
2026-06-12 05:08
mod_authnz_fcgi.html
26.93
KB
-rw-r--r--
2026-06-12 05:08
mod_authnz_ldap.html
86.06
KB
-rw-r--r--
2026-06-12 05:08
mod_authz_core.html
39.59
KB
-rw-r--r--
2026-06-12 05:08
mod_authz_dbd.html
18.13
KB
-rw-r--r--
2026-06-12 05:08
mod_authz_dbm.html
12.7
KB
-rw-r--r--
2026-06-12 05:08
mod_authz_groupfile.html
10.24
KB
-rw-r--r--
2026-06-12 05:08
mod_authz_host.html
13.12
KB
-rw-r--r--
2026-06-12 05:08
mod_authz_owner.html
11
KB
-rw-r--r--
2026-06-12 05:08
mod_authz_user.html
7.91
KB
-rw-r--r--
2026-06-12 05:08
mod_autoindex.html
70.35
KB
-rw-r--r--
2026-06-12 05:08
mod_brotli.html
22.65
KB
-rw-r--r--
2026-06-12 05:08
mod_buffer.html
8.76
KB
-rw-r--r--
2026-06-12 05:08
mod_cache.html
69.74
KB
-rw-r--r--
2026-06-12 05:08
mod_cache_disk.html
20.06
KB
-rw-r--r--
2026-06-12 05:08
mod_cache_socache.html
18.21
KB
-rw-r--r--
2026-06-12 05:08
mod_cern_meta.html
10.83
KB
-rw-r--r--
2026-06-12 05:08
mod_cgi.html
19.94
KB
-rw-r--r--
2026-06-12 05:08
mod_cgid.html
11.36
KB
-rw-r--r--
2026-06-12 05:08
mod_charset_lite.html
15.11
KB
-rw-r--r--
2026-06-12 05:08
mod_data.html
7.2
KB
-rw-r--r--
2026-06-12 05:08
mod_dav.html
19.88
KB
-rw-r--r--
2026-06-12 05:08
mod_dav_fs.html
10.54
KB
-rw-r--r--
2026-06-12 05:08
mod_dav_lock.html
9.51
KB
-rw-r--r--
2026-06-12 05:08
mod_dbd.html
24.89
KB
-rw-r--r--
2026-06-12 05:08
mod_deflate.html
31.15
KB
-rw-r--r--
2026-06-12 05:08
mod_dialup.html
7.2
KB
-rw-r--r--
2026-06-12 05:08
mod_dir.html
24.83
KB
-rw-r--r--
2026-06-12 05:08
mod_dumpio.html
9.41
KB
-rw-r--r--
2026-06-12 05:08
mod_echo.html
7.16
KB
-rw-r--r--
2026-06-12 05:08
mod_env.html
11.84
KB
-rw-r--r--
2026-06-12 05:08
mod_example_hooks.html
11.01
KB
-rw-r--r--
2026-06-12 05:08
mod_expires.html
17.21
KB
-rw-r--r--
2026-06-12 05:08
mod_ext_filter.html
18.05
KB
-rw-r--r--
2026-06-12 05:08
mod_file_cache.html
15.2
KB
-rw-r--r--
2026-06-12 05:08
mod_filter.html
33.35
KB
-rw-r--r--
2026-06-12 05:08
mod_headers.html
34.06
KB
-rw-r--r--
2026-06-12 05:08
mod_heartbeat.html
9.29
KB
-rw-r--r--
2026-06-12 05:08
mod_heartmonitor.html
11.92
KB
-rw-r--r--
2026-06-12 05:08
mod_http2.html
75.84
KB
-rw-r--r--
2026-06-12 05:08
mod_ident.html
9.74
KB
-rw-r--r--
2026-06-12 05:08
mod_imagemap.html
21.06
KB
-rw-r--r--
2026-06-12 05:08
mod_include.html
59.69
KB
-rw-r--r--
2026-06-12 05:08
mod_info.html
14.52
KB
-rw-r--r--
2026-06-12 05:08
mod_isapi.html
23.44
KB
-rw-r--r--
2026-06-12 05:08
mod_lbmethod_bybusyness.html
7.6
KB
-rw-r--r--
2026-06-12 05:08
mod_lbmethod_byrequests.html
12.3
KB
-rw-r--r--
2026-06-12 05:08
mod_lbmethod_bytraffic.html
7.95
KB
-rw-r--r--
2026-06-12 05:08
mod_lbmethod_heartbeat.html
8.02
KB
-rw-r--r--
2026-06-12 05:08
mod_ldap.html
50.89
KB
-rw-r--r--
2026-06-12 05:08
mod_log_config.html
40.02
KB
-rw-r--r--
2026-06-12 05:08
mod_log_debug.html
9.95
KB
-rw-r--r--
2026-06-12 05:08
mod_log_forensic.html
13.8
KB
-rw-r--r--
2026-06-12 05:08
mod_logio.html
10.98
KB
-rw-r--r--
2026-06-12 05:08
mod_lua.html
93.06
KB
-rw-r--r--
2026-06-12 05:08
mod_macro.html
15.29
KB
-rw-r--r--
2026-06-12 05:08
mod_md.html
109.91
KB
-rw-r--r--
2026-06-12 05:08
mod_mime.html
66.05
KB
-rw-r--r--
2026-06-12 05:08
mod_mime_magic.html
16.52
KB
-rw-r--r--
2026-06-12 05:08
mod_negotiation.html
21.68
KB
-rw-r--r--
2026-06-12 05:08
mod_nw_ssl.html
9.27
KB
-rw-r--r--
2026-06-12 05:08
mod_privileges.html
29.36
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy.html
137.06
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_ajp.html
32.56
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_balancer.html
23.03
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_connect.html
9.85
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_express.html
13.19
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_fcgi.html
22.14
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_fdpass.html
7.2
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_ftp.html
18.84
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_hcheck.html
17.43
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_html.html
34.16
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_http.html
11.63
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_http2.html
10.05
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_scgi.html
14.49
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_uwsgi.html
8.15
KB
-rw-r--r--
2026-06-12 05:08
mod_proxy_wstunnel.html
10.73
KB
-rw-r--r--
2026-06-12 05:08
mod_ratelimit.html
6.72
KB
-rw-r--r--
2026-06-12 05:08
mod_reflector.html
8.28
KB
-rw-r--r--
2026-06-12 05:08
mod_remoteip.html
26.54
KB
-rw-r--r--
2026-06-12 05:08
mod_reqtimeout.html
12.49
KB
-rw-r--r--
2026-06-12 05:08
mod_request.html
9.93
KB
-rw-r--r--
2026-06-12 05:08
mod_rewrite.html
82.27
KB
-rw-r--r--
2026-06-12 05:08
mod_sed.html
11.53
KB
-rw-r--r--
2026-06-12 05:08
mod_session.html
35.31
KB
-rw-r--r--
2026-06-12 05:08
mod_session_cookie.html
13.55
KB
-rw-r--r--
2026-06-12 05:08
mod_session_crypto.html
17.73
KB
-rw-r--r--
2026-06-12 05:08
mod_session_dbd.html
25.2
KB
-rw-r--r--
2026-06-12 05:08
mod_setenvif.html
23.09
KB
-rw-r--r--
2026-06-12 05:08
mod_slotmem_plain.html
7.76
KB
-rw-r--r--
2026-06-12 05:08
mod_slotmem_shm.html
8.36
KB
-rw-r--r--
2026-06-12 05:08
mod_so.html
15.71
KB
-rw-r--r--
2026-06-12 05:08
mod_socache_dbm.html
5.82
KB
-rw-r--r--
2026-06-12 05:08
mod_socache_dc.html
5.87
KB
-rw-r--r--
2026-06-12 05:08
mod_socache_memcache.html
8.34
KB
-rw-r--r--
2026-06-12 05:08
mod_socache_redis.html
10
KB
-rw-r--r--
2026-06-12 05:08
mod_socache_shmcb.html
5.9
KB
-rw-r--r--
2026-06-12 05:08
mod_speling.html
12.64
KB
-rw-r--r--
2026-06-12 05:08
mod_ssl.html
200.72
KB
-rw-r--r--
2026-06-12 05:08
mod_status.html
13.11
KB
-rw-r--r--
2026-06-12 05:08
mod_substitute.html
14.37
KB
-rw-r--r--
2026-06-12 05:08
mod_suexec.html
8.26
KB
-rw-r--r--
2026-06-12 05:08
mod_systemd.html
7.57
KB
-rw-r--r--
2026-06-12 05:08
mod_unique_id.html
14.89
KB
-rw-r--r--
2026-06-12 05:08
mod_unixd.html
14.69
KB
-rw-r--r--
2026-06-12 05:08
mod_userdir.html
13.57
KB
-rw-r--r--
2026-06-12 05:08
mod_usertrack.html
19.68
KB
-rw-r--r--
2026-06-12 05:08
mod_version.html
10.05
KB
-rw-r--r--
2026-06-12 05:08
mod_vhost_alias.html
22.43
KB
-rw-r--r--
2026-06-12 05:08
mod_watchdog.html
7.73
KB
-rw-r--r--
2026-06-12 05:08
mod_xml2enc.html
15.3
KB
-rw-r--r--
2026-06-12 05:08
module-dict.html
9.77
KB
-rw-r--r--
2026-06-12 05:08
mpm_common.html
75.9
KB
-rw-r--r--
2026-06-12 05:08
mpm_netware.html
9.82
KB
-rw-r--r--
2026-06-12 05:08
mpm_winnt.html
10.58
KB
-rw-r--r--
2026-06-12 05:08
mpmt_os2.html
7.5
KB
-rw-r--r--
2026-06-12 05:08
overrides.html
69.49
KB
-rw-r--r--
2026-06-12 05:08
prefork.html
17.67
KB
-rw-r--r--
2026-06-12 05:08
quickreference.html
199.29
KB
-rw-r--r--
2026-06-12 05:08
worker.html
16.88
KB
-rw-r--r--
2026-06-12 05:08
Save
Rename
<!DOCTYPE html SYSTEM "about:legacy-compat"> <html lang="en"><head><META http-equiv="Content-Type" content="text/html; charset=UTF-8"> <meta content="width=device-width, initial-scale=1" name="viewport"> <!-- XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX This file is generated from xml source: DO NOT EDIT XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX --> <title>mod_authz_core - Apache HTTP Server Version 2.4</title> <link href="../../style/css/manual.css" rel="stylesheet" media="all" type="text/css" title="Main stylesheet"> <link href="../../style/css/manual-loose-100pc.css" rel="alternate stylesheet" media="all" type="text/css" title="No Sidebar - Default font size"> <link href="../../style/css/manual-print.css" rel="stylesheet" media="print" type="text/css"><link rel="stylesheet" type="text/css" href="../../style/css/prettify.css"> <script src="../../style/scripts/prettify.min.js"> </script> <link href="../../images/favicon.png" rel="shortcut icon"></head> <body> <div id="page-header"> <p class="menu"><a href="../mod/index.html">Modules</a> | <a href="../mod/quickreference.html">Directives</a> | <a href="https://cwiki.apache.org/confluence/display/httpd/FAQ">FAQ</a> | <a href="../glossary.html">Glossary</a> | <a href="../sitemap.html">Sitemap</a> | <a href="https://bz.apache.org/bugzilla/enter_bug.cgi?product=Apache%20httpd-2">Report a bug</a></p> <p class="apache">Apache HTTP Server Version 2.4</p> <img alt="" src="../../images/feather.png"></div> <div class="up"><a href="./index.html"><img title="<-" alt="<-" src="../../images/left.gif"></a></div> <div id="path"> <a href="https://www.apache.org/">Apache</a> > <a href="https://httpd.apache.org/">HTTP Server</a> > <a href="https://httpd.apache.org/docs/">Documentation</a> > <a href="../index.html">Version 2.4</a> > <a href="./index.html">Modules</a></div> <div id="page-content"> <div id="preamble"><h1>Apache Module mod_authz_core</h1> <button aria-label="Toggle language list" class="lang-toggle"><svg xmlns="http://www.w3.org/2000/svg" stroke-width="2" stroke="currentColor" fill="none" viewBox="0 0 24 24" height="16" width="16"><circle r="10" cy="12" cx="12"/><line y2="12" x2="22" y1="12" x1="2"/><path d="M12 2a15.3 15.3 0 0 1 4 10 15.3 15.3 0 0 1-4 10 15.3 15.3 0 0 1-4-10 15.3 15.3 0 0 1 4-10z"/></svg></button> <div class="toplang"> <p><span>Available Languages: </span><a href="../../en/mod/mod_authz_core.html" title="English"> en </a> | <a href="../../fr/mod/mod_authz_core.html" hreflang="fr" rel="alternate" title="Français"> fr </a></p> </div> <table class="module"><tr><th><a href="module-dict.html#Description">Description:</a></th><td>Core Authorization</td></tr> <tr><th><a href="module-dict.html#Status">Status:</a></th><td>Base</td></tr> <tr><th><a href="module-dict.html#ModuleIdentifier">Module Identifier:</a></th><td>authz_core_module</td></tr> <tr><th><a href="module-dict.html#SourceFile">Source File:</a></th><td>mod_authz_core.c</td></tr> <tr><th><a href="module-dict.html#Compatibility">Compatibility:</a></th><td>Available in Apache HTTPD 2.3 and later</td></tr></table> <h3>Summary</h3> <p>This module provides core authorization capabilities so that authenticated users can be allowed or denied access to portions of the web site. <code class="module"><a href="../mod/mod_authz_core.html">mod_authz_core</a></code> provides the functionality to register various authorization providers. It is usually used in conjunction with an authentication provider module such as <code class="module"><a href="../mod/mod_authn_file.html">mod_authn_file</a></code> and an authorization module such as <code class="module"><a href="../mod/mod_authz_user.html">mod_authz_user</a></code>. It also allows for advanced logic to be applied to the authorization processing.</p> </div> <div id="quickview"><h3>Topics</h3> <ul id="topics"> <li><img alt="" src="../../images/down.gif"> <a href="#logic">Authorization Containers</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#authzresults">Authorization Result States</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#requiredirectives">The Require Directives</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#authzalias">Creating Authorization Provider Aliases</a></li> </ul><h3 class="directives">Directives</h3> <ul id="toc"> <li><img alt="" src="../../images/down.gif"> <a href="#authmerging">AuthMerging</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#authzprovideralias"><AuthzProviderAlias></a></li> <li><img alt="" src="../../images/down.gif"> <a href="#authzsendforbiddenonfailure">AuthzSendForbiddenOnFailure</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#require">Require</a></li> <li><img alt="" src="../../images/down.gif"> <a href="#requireall"><RequireAll></a></li> <li><img alt="" src="../../images/down.gif"> <a href="#requireany"><RequireAny></a></li> <li><img alt="" src="../../images/down.gif"> <a href="#requirenone"><RequireNone></a></li> </ul> <h3>Bugfix checklist</h3><ul class="seealso"><li><a href="https://www.apache.org/dist/httpd/CHANGES_2.4">httpd changelog</a></li><li><a href="https://bz.apache.org/bugzilla/buglist.cgi?bug_status=__open__&list_id=144532&product=Apache%20httpd-2&query_format=specific&order=changeddate%20DESC%2Cpriority%2Cbug_severity&component=mod_authz_core">Known issues</a></li><li><a href="https://bz.apache.org/bugzilla/enter_bug.cgi?product=Apache%20httpd-2&component=mod_authz_core">Report a bug</a></li></ul></div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="logic">Authorization Containers <a title="Permanent link" href="#logic" class="permalink">¶</a></h2> <p>The authorization container directives <code class="directive"><a href="#requireall"><RequireAll></a></code>, <code class="directive"><a href="#requireany"><RequireAny></a></code> and <code class="directive"><a href="#requirenone"><RequireNone></a></code> may be combined with each other and with the <code class="directive"><a href="#require">Require</a></code> directive to express complex authorization logic.</p> <p>The example below expresses the following authorization logic. In order to access the resource, the user must either be the <code>superadmin</code> user, or belong to both the <code>admins</code> group and the <code>Administrators</code> LDAP group and either belong to the <code>sales</code> group or have the LDAP <code>dept</code> attribute <code>sales</code>. Furthermore, in order to access the resource, the user must not belong to either the <code>temps</code> group or the LDAP group <code>Temporary Employees</code>.</p> <pre class="prettyprint lang-config"><Directory "/www/mydocs"> <RequireAll> <RequireAny> Require user superadmin <RequireAll> Require group admins Require ldap-group "cn=Administrators,o=Airius" <RequireAny> Require group sales Require ldap-attribute dept="sales" </RequireAny> </RequireAll> </RequireAny> <RequireNone> Require group temps Require ldap-group "cn=Temporary Employees,o=Airius" </RequireNone> </RequireAll> </Directory></pre> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="authzresults">Authorization Result States <a title="Permanent link" href="#authzresults" class="permalink">¶</a></h2> <p>Each authorization provider returns one of three possible results when evaluating a <code class="directive"><a href="#require">Require</a></code> directive:</p> <dl> <dt><strong>Granted</strong></dt> <dd>The provider has verified that the request meets its requirements.</dd> <dt><strong>Denied</strong></dt> <dd>The provider has determined that the request does not meet its requirements.</dd> <dt><strong>Neutral</strong></dt> <dd>The provider has no opinion about the request. This can occur when a provider is not relevant to the request (e.g., a group-membership check when the request does not involve group-based authorization).</dd> </dl> <p>The authorization container directives interpret these three results as follows:</p> <table class="bordered"><tr class="header"><th>Container</th><th>Granted if...</th><th>Denied if...</th><th>Neutral treated as...</th></tr> <tr><td><code class="directive"><a href="#requireany"><RequireAny></a></code></td> <td>at least one provider grants</td> <td>all providers deny</td> <td>deny (does not satisfy the requirement)</td></tr> <tr class="odd"><td><code class="directive"><a href="#requireall"><RequireAll></a></code></td> <td>no provider denies (and at least one grants)</td> <td>any provider denies</td> <td>grant (does not block the requirement)</td></tr> <tr><td><code class="directive"><a href="#requirenone"><RequireNone></a></code></td> <td>no provider grants</td> <td>any provider grants</td> <td>grant (does not block)</td></tr> </table> <p>When a <code class="directive">Require</code> directive is negated with <code>not</code> (e.g., <code>Require not group temps</code>), a granted result is inverted to denied and vice versa, but a neutral result remains neutral. A negated directive can therefore never independently authorize a request.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="requiredirectives">The Require Directives <a title="Permanent link" href="#requiredirectives" class="permalink">¶</a></h2> <p><code class="module"><a href="../mod/mod_authz_core.html">mod_authz_core</a></code> provides some generic authorization providers which can be used with the <code class="directive"><a href="#require">Require</a></code> directive.</p> <h3 id="reqenv">Require env</h3> <p>The <code>env</code> provider allows access to the server to be controlled based on the existence of an <a href="../env.html">environment variable</a>. When <code>Require env <var>env-variable</var></code> is specified, then the request is allowed access if the environment variable <var>env-variable</var> exists. The server provides the ability to set environment variables in a flexible way based on characteristics of the client request using the directives provided by <code class="module"><a href="../mod/mod_setenvif.html">mod_setenvif</a></code>. Therefore, this directive can be used to allow access based on such factors as the clients <code>User-Agent</code> (browser type), <code>Referer</code>, or other HTTP request header fields.</p> <pre class="prettyprint lang-config">SetEnvIf User-Agent "^KnockKnock/2\.0" let_me_in <Directory "/docroot"> Require env let_me_in </Directory></pre> <p>In this case, browsers with a user-agent string beginning with <code>KnockKnock/2.0</code> will be allowed access, and all others will be denied.</p> <p>When the server looks up a path via an internal <a class="glossarylink" href="../glossary.html#subrequest" title="see glossary">subrequest</a> such as looking for a <code class="directive"><a href="../mod/mod_dir.html#directoryindex">DirectoryIndex</a></code> or generating a directory listing with <code class="module"><a href="../mod/mod_autoindex.html">mod_autoindex</a></code>, per-request environment variables are <em>not</em> inherited in the subrequest. Additionally, <code class="directive"><a href="../mod/mod_setenvif.html#setenvif">SetEnvIf</a></code> directives are not separately evaluated in the subrequest due to the API phases <code class="module"><a href="../mod/mod_setenvif.html">mod_setenvif</a></code> takes action in.</p> <h3 id="reqall">Require all</h3> <p>The <code>all</code> provider mimics the functionality that was previously provided by the 'Allow from all' and 'Deny from all' directives. This provider can take one of two arguments which are 'granted' or 'denied'. The following examples will grant or deny access to all requests.</p> <pre class="prettyprint lang-config">Require all granted</pre> <pre class="prettyprint lang-config">Require all denied</pre> <h3 id="reqmethod">Require method</h3> <p>The <code>method</code> provider allows using the HTTP method in authorization decisions. The GET and HEAD methods are treated as equivalent. The TRACE method is not available to this provider, use <code class="directive"><a href="../mod/core.html#traceenable">TraceEnable</a></code> instead.</p> <p>The following example will only allow GET, HEAD, POST, and OPTIONS requests:</p> <pre class="prettyprint lang-config">Require method GET POST OPTIONS</pre> <p>The following example will allow GET, HEAD, POST, and OPTIONS requests without authentication, and require a valid user for all other methods:</p> <pre class="prettyprint lang-config"><RequireAny> Require method GET POST OPTIONS Require valid-user </RequireAny></pre> <h3 id="reqexpr">Require expr</h3> <p>The <code>expr</code> provider allows basing authorization decisions on arbitrary expressions.</p> <pre class="prettyprint lang-config">Require expr "%{TIME_HOUR} -ge 9 && %{TIME_HOUR} -le 17"</pre> <pre class="prettyprint lang-config"><RequireAll> Require expr "!(%{QUERY_STRING} =~ /secret/)" Require expr "%{REQUEST_URI} in { '/example.cgi', '/other.cgi' }" </RequireAll></pre> <pre class="prettyprint lang-config">Require expr "!(%{QUERY_STRING} =~ /secret/) && %{REQUEST_URI} in { '/example.cgi', '/other.cgi' }"</pre> <p>The syntax is described in the <a href="../expr.html">ap_expr</a> documentation. Before httpd 2.4.16, the surrounding double-quotes MUST be omitted.</p> <p>Normally, the expression is evaluated before authentication. However, if the expression returns false and references the variable <code>%{REMOTE_USER}</code>, authentication will be performed and the expression will be re-evaluated.</p> </div><div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="section"> <h2 id="authzalias">Creating Authorization Provider Aliases <a title="Permanent link" href="#authzalias" class="permalink">¶</a></h2> <p>Extended authorization providers can be created within the configuration file and assigned an alias name. The alias providers can then be referenced through the <code class="directive"><a href="#require">Require</a></code> directive in the same way as a base authorization provider. Besides the ability to create and alias an extended provider, it also allows the same extended authorization provider to be referenced by multiple locations. </p> <h3 id="example">Example</h3> <p>The example below creates two different ldap authorization provider aliases based on the ldap-group authorization provider. This example allows a single authorization location to check group membership within multiple ldap hosts: </p> <pre class="prettyprint lang-config"><AuthzProviderAlias ldap-group ldap-group-alias1 "cn=my-group,o=ctx"> AuthLDAPBindDN "cn=youruser,o=ctx" AuthLDAPBindPassword yourpassword AuthLDAPUrl "ldap://ldap.host/o=ctx" </AuthzProviderAlias> <AuthzProviderAlias ldap-group ldap-group-alias2 "cn=my-other-group,o=dev"> AuthLDAPBindDN "cn=yourotheruser,o=dev" AuthLDAPBindPassword yourotherpassword AuthLDAPUrl "ldap://other.ldap.host/o=dev?cn" </AuthzProviderAlias> Alias "/secure" "/webpages/secure" <Directory "/webpages/secure"> AuthType Basic AuthName "LDAP Protected" AuthBasicProvider ldap AuthLDAPUrl "ldap://ldap.host/o=ctx" #implied OR operation Require ldap-group-alias1 Require ldap-group-alias2 </Directory></pre> </div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="directive-section"><h2 id="authmerging"><span id="AuthMerging">AuthMerging</span> Directive <a title="Permanent link" href="#authmerging" class="permalink">¶</a></h2> <table class="directive"> <tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Controls the manner in which each configuration section's authorization logic is combined with that of preceding configuration sections.</td></tr> <tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code>AuthMerging Off | And | Or</code></td></tr> <tr><th><a href="directive-dict.html#Default">Default:</a></th><td><code>AuthMerging Off</code></td></tr> <tr><th><a href="directive-dict.html#Context">Context:</a></th><td>directory, .htaccess</td></tr> <tr><th><a href="directive-dict.html#Override">Override:</a></th><td>AuthConfig</td></tr> <tr><th><a href="directive-dict.html#Status">Status:</a></th><td>Base</td></tr> <tr><th><a href="directive-dict.html#Module">Module:</a></th><td>mod_authz_core</td></tr> </table> <p>When authorization is enabled, it is normally inherited by each subsequent <a href="../sections.html#merging">configuration section</a>, unless a different set of authorization directives is specified. This is the default action, which corresponds to an explicit setting of <code>AuthMerging Off</code>.</p> <p>However, there may be circumstances in which it is desirable for a configuration section's authorization to be combined with that of its predecessor while configuration sections are being merged. Two options are available for this case, <code>And</code> and <code>Or</code>.</p> <p>When a configuration section contains <code>AuthMerging And</code> or <code>AuthMerging Or</code>, its authorization logic is combined with that of the nearest predecessor (according to the overall order of configuration sections) which also contains authorization logic as if the two sections were jointly contained within a <code class="directive"><a href="#requireall"><RequireAll></a></code> or <code class="directive"><a href="#requireany"><RequireAny></a></code> directive, respectively.</p> <div class="note">The setting of <code class="directive">AuthMerging</code> is not inherited outside of the configuration section in which it appears. In the following example, only users belonging to group <code>alpha</code> may access <code>/www/docs</code>. Users belonging to either groups <code>alpha</code> or <code>beta</code> may access <code>/www/docs/ab</code>. However, the default <code>Off</code> setting of <code class="directive">AuthMerging</code> applies to the <code class="directive"><a href="../mod/core.html#directory"><Directory></a></code> configuration section for <code>/www/docs/ab/gamma</code>, so that section's authorization directives override those of the preceding sections. Thus only users belong to the group <code>gamma</code> may access <code>/www/docs/ab/gamma</code>.</div> <pre class="prettyprint lang-config"><Directory "/www/docs"> AuthType Basic AuthName Documents AuthBasicProvider file AuthUserFile "/usr/local/apache/passwd/passwords" Require group alpha </Directory> <Directory "/www/docs/ab"> AuthMerging Or Require group beta </Directory> <Directory "/www/docs/ab/gamma"> Require group gamma </Directory></pre> </div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="directive-section"><h2 id="authzprovideralias"><span id="AuthzProviderAlias"><AuthzProviderAlias></span> Directive <a title="Permanent link" href="#authzprovideralias" class="permalink">¶</a></h2> <table class="directive"> <tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Enclose a group of directives that represent an extension of a base authorization provider and referenced by the specified alias</td></tr> <tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code><AuthzProviderAlias <var>baseProvider Alias Require-Parameters</var>> ... </AuthzProviderAlias> </code></td></tr> <tr><th><a href="directive-dict.html#Context">Context:</a></th><td>server config</td></tr> <tr><th><a href="directive-dict.html#Status">Status:</a></th><td>Base</td></tr> <tr><th><a href="directive-dict.html#Module">Module:</a></th><td>mod_authz_core</td></tr> </table> <p><code class="directive"><AuthzProviderAlias></code> and <code></AuthzProviderAlias></code> are used to enclose a group of authorization directives that can be referenced by the alias name using the directive <code class="directive"><a href="#require">Require</a></code>.</p> <p>If several parameters are needed in <var>Require-Parameters</var>, they must be enclosed in quotation marks. Otherwise, only the first one is taken into account.</p> <pre class="prettyprint lang-config"># In this example, for both addresses to be taken into account, they MUST be enclosed # between quotation marks <AuthzProviderAlias ip reject-ips "XXX.XXX.XXX.XXX YYY.YYY.YYY.YYY"> </AuthzProviderAlias> <Directory "/path/to/dir"> <RequireAll> Require not reject-ips Require all granted </RequireAll> </Directory></pre> </div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="directive-section"><h2 id="authzsendforbiddenonfailure"><span id="AuthzSendForbiddenOnFailure">AuthzSendForbiddenOnFailure</span> Directive <a title="Permanent link" href="#authzsendforbiddenonfailure" class="permalink">¶</a></h2> <table class="directive"> <tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Send '403 FORBIDDEN' instead of '401 UNAUTHORIZED' if authentication succeeds but authorization fails </td></tr> <tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code>AuthzSendForbiddenOnFailure On|Off</code></td></tr> <tr><th><a href="directive-dict.html#Default">Default:</a></th><td><code>AuthzSendForbiddenOnFailure Off</code></td></tr> <tr><th><a href="directive-dict.html#Context">Context:</a></th><td>directory, .htaccess</td></tr> <tr><th><a href="directive-dict.html#Status">Status:</a></th><td>Base</td></tr> <tr><th><a href="directive-dict.html#Module">Module:</a></th><td>mod_authz_core</td></tr> <tr><th><a href="directive-dict.html#Compatibility">Compatibility:</a></th><td>Available in Apache HTTPD 2.3.11 and later</td></tr> </table> <p>If authentication succeeds but authorization fails, Apache HTTPD will respond with an HTTP response code of '401 UNAUTHORIZED' by default. This usually causes browsers to display the password dialog to the user again, which is not wanted in all situations. <code class="directive">AuthzSendForbiddenOnFailure</code> allows to change the response code to '403 FORBIDDEN'.</p> <div class="warning"><h3>Security Warning</h3> <p>Modifying the response in case of missing authorization weakens the security of the password, because it reveals to a possible attacker, that his guessed password was right.</p> </div> </div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="directive-section"><h2 id="require"><span id="Require">Require</span> Directive <a title="Permanent link" href="#require" class="permalink">¶</a></h2> <table class="directive"> <tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Tests whether an authenticated user is authorized by an authorization provider.</td></tr> <tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code>Require [not] <var>entity-name</var> [<var>entity-name</var>] ...</code></td></tr> <tr><th><a href="directive-dict.html#Context">Context:</a></th><td>directory, .htaccess</td></tr> <tr><th><a href="directive-dict.html#Override">Override:</a></th><td>AuthConfig</td></tr> <tr><th><a href="directive-dict.html#Status">Status:</a></th><td>Base</td></tr> <tr><th><a href="directive-dict.html#Module">Module:</a></th><td>mod_authz_core</td></tr> </table> <p>This directive tests whether an authenticated user is authorized according to a particular authorization provider and the specified restrictions. <code class="module"><a href="../mod/mod_authz_core.html">mod_authz_core</a></code> provides the following generic authorization providers:</p> <dl> <dt><code>Require all granted</code></dt> <dd>Access is allowed unconditionally.</dd> <dt><code>Require all denied</code></dt> <dd>Access is denied unconditionally.</dd> <dt><code>Require env <var>env-var</var> [<var>env-var</var>] ...</code></dt> <dd>Access is allowed only if one of the given environment variables is set.</dd> <dt><code>Require method <var>http-method</var> [<var>http-method</var>] ...</code></dt> <dd>Access is allowed only for the given HTTP methods.</dd> <dt><code>Require expr <var>expression</var> </code></dt> <dd>Access is allowed if <var>expression</var> evaluates to true.</dd> </dl> <p>Some of the allowed syntaxes provided by <code class="module"><a href="../mod/mod_authz_user.html">mod_authz_user</a></code>, <code class="module"><a href="../mod/mod_authz_host.html">mod_authz_host</a></code>, and <code class="module"><a href="../mod/mod_authz_groupfile.html">mod_authz_groupfile</a></code> are:</p> <dl> <dt><code>Require user <var>userid</var> [<var>userid</var>] ...</code></dt> <dd>Only the named users can access the resource.</dd> <dt><code>Require group <var>group-name</var> [<var>group-name</var>] ...</code></dt> <dd>Only users in the named groups can access the resource.</dd> <dt><code>Require valid-user</code></dt> <dd>All valid users can access the resource.</dd> <dt><code>Require ip 10 172.20 192.168.2</code></dt> <dd>Clients in the specified IP address ranges can access the resource.</dd> <dt><code>Require forward-dns dynamic.example.org</code></dt> <dd>A client the IP of which is resolved from the name dynamic.example.org will be granted access. </dd> </dl> <p>Other authorization modules that implement require options include <code class="module"><a href="../mod/mod_authnz_ldap.html">mod_authnz_ldap</a></code>, <code class="module"><a href="../mod/mod_authz_dbm.html">mod_authz_dbm</a></code>, <code class="module"><a href="../mod/mod_authz_dbd.html">mod_authz_dbd</a></code>, <code class="module"><a href="../mod/mod_authz_owner.html">mod_authz_owner</a></code> and <code class="module"><a href="../mod/mod_ssl.html">mod_ssl</a></code>.</p> <p>In most cases, for a complete authentication and authorization configuration, <code class="directive">Require</code> must be accompanied by <code class="directive"><a href="../mod/mod_authn_core.html#authname">AuthName</a></code>, <code class="directive"><a href="../mod/mod_authn_core.html#authtype">AuthType</a></code> and <code class="directive"><a href="../mod/mod_auth_basic.html#authbasicprovider">AuthBasicProvider</a></code> or <code class="directive"><a href="../mod/mod_auth_digest.html#authdigestprovider">AuthDigestProvider</a></code> directives, and directives such as <code class="directive"><a href="../mod/mod_authn_file.html#authuserfile">AuthUserFile</a></code> and <code class="directive"><a href="../mod/mod_authz_groupfile.html#authgroupfile">AuthGroupFile</a></code> (to define users and groups) in order to work correctly. Example:</p> <pre class="prettyprint lang-config">AuthType Basic AuthName "Restricted Resource" AuthBasicProvider file AuthUserFile "/web/users" AuthGroupFile "/web/groups" Require group admin</pre> <p>Access controls which are applied in this way are effective for <strong>all</strong> methods. <strong>This is what is normally desired.</strong> If you wish to apply access controls only to specific methods, while leaving other methods unprotected, then place the <code class="directive">Require</code> statement into a <code class="directive"><a href="../mod/core.html#limit"><Limit></a></code> section.</p> <p>The result of the <code class="directive">Require</code> directive may be negated through the use of the <code>not</code> option. As with the other negated authorization directive <code class="directive"><RequireNone></code>, when the <code class="directive">Require</code> directive is negated it can only fail or return a neutral result, and therefore may never independently authorize a request.</p> <p>In the following example, all users in the <code>alpha</code> and <code>beta</code> groups are authorized, except for those who are also in the <code>reject</code> group.</p> <pre class="prettyprint lang-config"><Directory "/www/docs"> <RequireAll> Require group alpha beta Require not group reject </RequireAll> </Directory></pre> <p>When multiple <code class="directive">Require</code> directives are used in a single <a href="../sections.html#merging">configuration section</a> and are not contained in another authorization directive like <code class="directive"><a href="#requireall"><RequireAll></a></code>, they are implicitly contained within a <code class="directive"><a href="#requireany"><RequireAny></a></code> directive. Thus the first one to authorize a user authorizes the entire request, and subsequent <code class="directive">Require</code> directives are ignored.</p> <div class="warning"><h3>Security Warning</h3> <p>Exercise caution when setting authorization directives in <code class="directive"><a href="../mod/core.html#location">Location</a></code> sections that overlap with content served out of the filesystem. By default, these <a href="../sections.html#merging">configuration sections</a> overwrite authorization configuration in <code class="directive"><a href="../mod/core.html#directory">Directory</a></code>, and <code class="directive"><a href="../mod/core.html#files">Files</a></code> sections.</p> <p>The <code class="directive"><a href="#authmerging">AuthMerging</a></code> directive can be used to control how authorization configuration sections are merged.</p> </div> <h3>See also</h3> <ul> <li><a href="../howto/access.html">Access Control howto</a></li> <li><a href="#logic">Authorization Containers</a></li> <li><a href="#authzresults">Authorization Result States</a></li> <li><code class="module"><a href="../mod/mod_authn_core.html">mod_authn_core</a></code></li> <li><code class="module"><a href="../mod/mod_authz_host.html">mod_authz_host</a></code></li> </ul> </div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="directive-section"><h2 id="requireall"><span id="RequireAll"><RequireAll></span> Directive <a title="Permanent link" href="#requireall" class="permalink">¶</a></h2> <table class="directive"> <tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Enclose a group of authorization directives of which none must fail and at least one must succeed for the enclosing directive to succeed.</td></tr> <tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code><RequireAll> ... </RequireAll></code></td></tr> <tr><th><a href="directive-dict.html#Context">Context:</a></th><td>directory, .htaccess</td></tr> <tr><th><a href="directive-dict.html#Override">Override:</a></th><td>AuthConfig</td></tr> <tr><th><a href="directive-dict.html#Status">Status:</a></th><td>Base</td></tr> <tr><th><a href="directive-dict.html#Module">Module:</a></th><td>mod_authz_core</td></tr> </table> <p><code class="directive"><RequireAll></code> and <code></RequireAll></code> are used to enclose a group of authorization directives of which none must fail and at least one must succeed in order for the <code class="directive"><RequireAll></code> directive to succeed.</p> <p>If none of the directives contained within the <code class="directive"><RequireAll></code> directive fails, and at least one succeeds, then the <code class="directive"><RequireAll></code> directive succeeds. If none succeed and none fail, then it returns a neutral result. In all other cases, it fails.</p> <h3>See also</h3> <ul> <li><a href="#logic">Authorization Containers</a></li> <li><a href="#authzresults">Authorization Result States</a></li> <li><a href="../howto/auth.html">Authentication, Authorization, and Access Control</a></li> </ul> </div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="directive-section"><h2 id="requireany"><span id="RequireAny"><RequireAny></span> Directive <a title="Permanent link" href="#requireany" class="permalink">¶</a></h2> <table class="directive"> <tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Enclose a group of authorization directives of which one must succeed for the enclosing directive to succeed.</td></tr> <tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code><RequireAny> ... </RequireAny></code></td></tr> <tr><th><a href="directive-dict.html#Context">Context:</a></th><td>directory, .htaccess</td></tr> <tr><th><a href="directive-dict.html#Override">Override:</a></th><td>AuthConfig</td></tr> <tr><th><a href="directive-dict.html#Status">Status:</a></th><td>Base</td></tr> <tr><th><a href="directive-dict.html#Module">Module:</a></th><td>mod_authz_core</td></tr> </table> <p><code class="directive"><RequireAny></code> and <code></RequireAny></code> are used to enclose a group of authorization directives of which one must succeed in order for the <code class="directive"><RequireAny></code> directive to succeed.</p> <p>If one or more of the directives contained within the <code class="directive"><RequireAny></code> directive succeed, then the <code class="directive"><RequireAny></code> directive succeeds. If none succeed and none fail, then it returns a neutral result. In all other cases, it fails.</p> <div class="note">Because negated authorization directives are unable to return a successful result, they can not significantly influence the result of a <code class="directive"><RequireAny></code> directive. (At most they could cause the directive to fail in the case where they failed and all other directives returned a neutral value.) Therefore negated authorization directives are not permitted within a <code class="directive"><RequireAny></code> directive.</div> <h3>See also</h3> <ul> <li><a href="#logic">Authorization Containers</a></li> <li><a href="#authzresults">Authorization Result States</a></li> <li><a href="../howto/auth.html">Authentication, Authorization, and Access Control</a></li> </ul> </div> <div class="top"><a href="#page-header"><img alt="top" src="../../images/up.gif"></a></div> <div class="directive-section"><h2 id="requirenone"><span id="RequireNone"><RequireNone></span> Directive <a title="Permanent link" href="#requirenone" class="permalink">¶</a></h2> <table class="directive"> <tr><th><a href="directive-dict.html#Description">Description:</a></th><td>Enclose a group of authorization directives of which none must succeed for the enclosing directive to not fail.</td></tr> <tr><th><a href="directive-dict.html#Syntax">Syntax:</a></th><td><code><RequireNone> ... </RequireNone></code></td></tr> <tr><th><a href="directive-dict.html#Context">Context:</a></th><td>directory, .htaccess</td></tr> <tr><th><a href="directive-dict.html#Override">Override:</a></th><td>AuthConfig</td></tr> <tr><th><a href="directive-dict.html#Status">Status:</a></th><td>Base</td></tr> <tr><th><a href="directive-dict.html#Module">Module:</a></th><td>mod_authz_core</td></tr> </table> <p><code class="directive"><RequireNone></code> and <code></RequireNone></code> are used to enclose a group of authorization directives of which none must succeed in order for the <code class="directive"><RequireNone></code> directive to not fail.</p> <p>If one or more of the directives contained within the <code class="directive"><RequireNone></code> directive succeed, then the <code class="directive"><RequireNone></code> directive fails. In all other cases, it returns a neutral result. Thus as with the other negated authorization directive <code>Require not</code>, it can never independently authorize a request because it can never return a successful result. It can be used, however, to restrict the set of users who are authorized to access a resource.</p> <div class="note">Because negated authorization directives are unable to return a successful result, they can not significantly influence the result of a <code class="directive"><RequireNone></code> directive. Therefore negated authorization directives are not permitted within a <code class="directive"><RequireNone></code> directive.</div> <h3>See also</h3> <ul> <li><a href="#logic">Authorization Containers</a></li> <li><a href="#authzresults">Authorization Result States</a></li> <li><a href="../howto/auth.html">Authentication, Authorization, and Access Control</a></li> </ul> </div> </div> <div class="bottomlang"> <p><span>Available Languages: </span><a href="../../en/mod/mod_authz_core.html" title="English"> en </a> | <a href="../../fr/mod/mod_authz_core.html" hreflang="fr" rel="alternate" title="Français"> fr </a></p> </div><div id="footer"> <p class="apache">Copyright 2026 The Apache Software Foundation.<br>Licensed under the <a href="https://www.apache.org/licenses/LICENSE-2.0">Apache License, Version 2.0</a>.</p> <p class="menu"><a href="../mod/index.html">Modules</a> | <a href="../mod/quickreference.html">Directives</a> | <a href="https://cwiki.apache.org/confluence/display/httpd/FAQ">FAQ</a> | <a href="../glossary.html">Glossary</a> | <a href="../sitemap.html">Sitemap</a> | <a href="https://bz.apache.org/bugzilla/enter_bug.cgi?product=Apache%20httpd-2">Report a bug</a></p></div><script><!--//--><![CDATA[//><!-- if (typeof(prettyPrint) !== 'undefined') { prettyPrint(); } var langToggle = document.querySelector('.lang-toggle'); var topLang = document.querySelector('.toplang'); if (langToggle && topLang) { langToggle.addEventListener('click', function() { topLang.classList.toggle('open'); }); } var qv = document.getElementById('quickview'); if (qv) { document.body.appendChild(qv); var qvBtn = document.createElement('button'); qvBtn.className = 'qv-toggle'; qvBtn.setAttribute('aria-label', 'Toggle page navigation'); qvBtn.innerHTML = '☰'; document.body.appendChild(qvBtn); qvBtn.addEventListener('click', function() { var isOpen = qv.classList.toggle('open'); if (isOpen) { qv.style.top = window.scrollY + 10 + 'px'; } }); window.addEventListener('scroll', function() { qv.classList.remove('open'); }); } //--><!]]></script> </body></html>