• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question Nginx behaving strangely with auth_basic

Dirk

Basic Pleskian
I have the following line in nginx. conf:
location ^~ /internal/ {auth_basic "Restricted"; auth_basic_user_file /var/www/. htpasswd; }

This works well, but the following problem occurs. If I'm in the internal area and now access a php file in the directory, it won't be executed but downloaded. As soon as I comment out the above line, everything works fine again.
Now, if I skip the ^ so that the line looks like this:
location ~ /internal/ {auth_basic "Restricted"; auth_basic_user_file /var/www/. htpasswd; }
Then the php will be executed again, but you can now access individual files directly in the protected directory - so you can't access www.domain.de/internal without password, but you can access www.domain.de/internal/bild1.jpg

Does anyone have an idea how I can protect the entire directory and its contents and still the php runs normally?
 
Back
Top