Handlers and Downloads

AddHandler, SetHandler and Forcing Downloads

A handler is the action that produces a response: default-handler sends the file as it is, and mod_php registers application/x-httpd-php. AddHandler name .ext attaches one by extension; SetHandler name applies one to everything in its container, and SetHandler None cancels it.

Prefer SetHandler in an anchored <FilesMatch>. The mod_mime documentation warns that a file with several extensions picks up the handler of any of them, so with AddHandler an extension in the middle of a name decides how the file is processed. Ubuntu 225 's php8.5.conf uses <FilesMatch "\.ph(?:ar|p|tml)$">, which tests the final extension only (for PHP-FPM, see PHP-FPM via proxy_fcgi).

Two safety switches follow. In an uploads folder, SetHandler default-handler plus ForceType text/plain for script extensions sends those files as text, never runs them. To make a browser save a file, send ForceType application/octet-stream and Header set Content-Disposition "attachment".