Ian Bicking: the old part of his blog

Re: Help me please: Apache auth

Which ordering do you have in the Order directive?

You will need to write a stanza for all directories at the level for which you want relaxed permissions. A brief example:

consider the tree bar,baz,qux in foo using groups: elect and world

Order Allow Deny
<Directory foo/bar>
 Require group elect
</Directory>
<Directory foo/baz>
 Require group world
</Directory>
<Directory foo/qux> #this lets anyone in!! it is wrong
 Require valid-user
 Require group elect
</Directory>

I find that when it comes to securing resources like this explicit is better than implicit ;-)

Comment on Help me please: Apache auth
by Larry