How to password-protect a folder
Before protecting a folder
Directory protection is useful for development copies, private downloads, staging sites, internal documents and websites awaiting launch. It isn't a replacement for application login security.
Use HTTPS before entering the folder password. Free SSL is issued automatically once the domain points to Webway.
Protect a folder in cPanel
- Sign in to cPanel.
- Open Security.
- Select Directory Privacy.
- Browse to the folder you want to protect and select it.
- Enable password protection.
- Enter a name for the protected area.
- Save.
- Create an authorised username and strong password.
- Save the user.
Open the folder in a private browser window and confirm that it asks for a login.
Protect a folder in DirectAdmin
- Sign in to DirectAdmin.
- Open Advanced Features.
- Select Password Protected Directories.
- Select the folder.
- Enable protection.
- Enter a name for the protected area.
- Create an authorised username and strong password.
- Save.
Test the folder in a private browser window.
Choose the correct folder
- cPanel main website:
/home/USERNAME/public_html - DirectAdmin:
/home/USERNAME/domains/DOMAIN/public_html
Protect only the folder that needs restricted access. Protecting public_html itself locks the entire website.
Use a separate password
Don't reuse your client area, control panel, email or WordPress password.
Application routes may behave differently
Folder protection works at the web-server level. A page created by WordPress or another framework may not correspond to a real folder. In that case, protect the application itself or its whole folder.
Remove protection
Return to the same tool, select the folder, turn protection off, save, and remove unused users. Test in a private window.
Don't manually delete the generated .htaccess or password files unless you understand how the protection was set up.
Did this answer it?