Directory, Files, Location

Directory, Files and Location Compared

<Directory> matches a filesystem path and everything below it. <Files> matches a file's base name wherever it sits and is the only one of the three allowed in .htaccess, which makes it the tool for blocking .env files and backups (Protecting Sensitive Files). <Location> matches the URL the client sent, before Apache 129 knows which file, if any, it maps to, so it suits content with no file behind it, as in Ubuntu 225 's <Location /server-status>.

The difference matters once two URLs reach the same file. Here site-b gains an Alias publishing a folder under a second path, and a <Location> that tries to protect it:

Protecting a URL instead of the files behind itApache config
Alias "/mirror" "/var/www/site-b/private"
<Location "/private">
  Require all denied
</Location>
Requesting the same file under both URLsApache config
for u in /private/secret.txt /mirror/secret.txt; do
  printf '%-22s ' "$u"
  curl -s -o /dev/null -w '%{http_code}\n' -H 'Host: site-b.example' "http://localhost:8101$u"
done
Output
/private/secret.txt    403
/mirror/secret.txt     200

The second URL walks straight past the rule. With <Directory "/var/www/site-b/private"> in place of the <Location>, the same loop returns 403 for both URLs, because the rule now follows the files. A case-insensitive filesystem opens the same gap (/PRIVATE/ on a Mac), which is why the manual says never to use <Location> to restrict files, with one safe exception: <Location "/">, which matches everything.