IP and Referrer Checks

IP Allow Lists and Referrer Checks

Require ip takes addresses, prefixes (10.1), CIDR blocks and IPv6 networks; prefer it to Require host, which costs a double reverse DNS lookup. Here the office (played by 127.0.0.1) needs no password, everyone else logs in, and one network is banned:

Office walks in, everyone else logs in, one network bannedApache config
# /var/www/example/staff/.htaccess - Needs: AllowOverride AuthConfig
AuthType Basic
AuthName "Staff"
AuthUserFile /etc/apache2/auth/htpasswd
<RequireAll>
  Require not ip 127.0.0.3 192.0.2.0/24
  <RequireAny>
    Require ip 127.0.0.1 198.51.100.0/24 2001:db8:42::/48
    Require valid-user
  </RequireAny>
</RequireAll>

Requests from three client addresses, with and without Alice's login, returned:

Output of 66
127.0.0.1                        200
127.0.0.2                        401
127.0.0.2 -u alice:Tr0ub4dor&3   200
127.0.0.3 -u alice:Tr0ub4dor&3   403

This replaces Apache 2.2 129 's Satisfy Any and Order/Allow/Deny; do not mix the old lines in. Behind a proxy every request comes from the proxy until RemoteIPHeader in the server configuration (ProxyPass) restores the client's address.

A referrer check tests which page the link was on:

Downloads only for visitors arriving from the site's own pagesApache config
# /var/www/example/downloads/.htaccess - Needs: AllowOverride AuthConfig
Require expr "%{HTTP_REFERER} =~ m#^https?://(www\.)?example\.com(:\d+)?/#"

A Referer of https://example.com/prices.html got 200; none, https://evil.example.net/ and https://example.com.evil.net/ got 403. It only filters nuisances: clients forge the header, and Referrer-Policy: no-referrer pages send none.