Martin Pool
Sun Apr 16 02:59:19 EDT 2000

On Fri, 14 Apr 2000, Luke Grant wrote:

> or you could put the following entre into your httpd.conf file.
> <Directory /directory/you/want/restricted>
>     AllowOverride FileInfo AuthConfig Limit
>     Options MultiViews Indexes SymLinksIfOwnerMatch IncludesNoExec
>     order deny, allow
>     deny from all
>     allow from
>     </Limit>
> </Directory>

Bloody!  You're obviously being paid by the byte.  :-)

I'd prefer to use <Location> rather than <Directory> if I'm trying to
restrict by logical location: the intention is clearer, and it won't break
if you move the webserver to a different directory.

I think the configuration you give will allow people to e.g. do a HEAD on
/secret/index.html, which is probably not what the guy wants.  There's no
need for a <Limit> unless you care about restricting some methods more
than others.

