Require ip takes addresses, prefixes (10.1), CIDR blocks and IPv6 networks; prefer it to Require host, which costs a double reverse DNS lookup. Here the office (played by 127.0.0.1) needs no password, everyone else logs in, and one network is banned:
# /var/www/example/staff/.htaccess - Needs: AllowOverride AuthConfig
AuthType Basic
AuthName "Staff"
AuthUserFile /etc/apache2/auth/htpasswd
<RequireAll>
Require not ip 127.0.0.3 192.0.2.0/24
<RequireAny>
Require ip 127.0.0.1 198.51.100.0/24 2001:db8:42::/48
Require valid-user
</RequireAny>
</RequireAll>Requests from three client addresses, with and without Alice's login, returned:
127.0.0.1 200 127.0.0.2 401 127.0.0.2 -u alice:Tr0ub4dor&3 200 127.0.0.3 -u alice:Tr0ub4dor&3 403
This replaces Apache 2.2 129 's Satisfy Any and Order/Allow/Deny; do not mix the old lines in. Behind a proxy every request comes from the proxy until RemoteIPHeader in the server configuration (ProxyPass) restores the client's address.
A referrer check tests which page the link was on:
# /var/www/example/downloads/.htaccess - Needs: AllowOverride AuthConfig
Require expr "%{HTTP_REFERER} =~ m#^https?://(www\.)?example\.com(:\d+)?/#"A Referer of https://example.com/prices.html got 200; none, https://evil.example.net/ and https://example.com.evil.net/ got 403. It only filters nuisances: clients forge the header, and Referrer-Policy: no-referrer pages send none.