Morning,
I want to use mod_auth for apache2 to restrict access to a directory on
a website. I also want to use mod_rewrite to force such authentication
to be over https. I have the following in dir/.htaccess:
RewriteEngine On
RewriteCond %{HTTPS} !^on$
RewriteRule ^(.*)$ https://%{HTTP_HOST}/dir/$1
AuthType Basic
AuthName "private thingum"
require user username
However, what happens is that i'm prompted for the username and password
before i'm redirected to ssl, which is useless. Is there any way i can
get the rewrite to happen before the auth? Thanks,
Steve
Maintained by the ILUG website team. The aim of Linux.ie is to
support and help commercial and private users of Linux in Ireland. You can
display ILUG news in your own webpages, read backend
information to find out how. Networking services kindly provided by HEAnet, server kindly donated by
Dell. Linux is a trademark of Linus Torvalds,
used with permission. No penguins were harmed in the production or maintenance
of this highly praised website. Looking for the
Indian Linux Users' Group? Try here. If you've read all this and aren't a lawyer: you should be!