DirectoryIndex

DirectoryIndex and Turning Off Automatic Indexes

For a directory URL, mod_dir serves the first file in the DirectoryIndex list that exists; if none does and Options Indexes is on, mod_autoindex generates a listing. Ubuntu 225 's dir.conf lists index.html index.cgi index.pl index.php index.xhtml index.htm, and apache2.conf turns Indexes on for /var/www/. On the test site, /files/ therefore returned an "Index of /files" page linking db-backup.sql, notes.txt and report-2026-q3.csv: the backup was one click away. Three lines fix it:

Index files in a fixed order, and no listingsApache config
# /var/www/example/.htaccess: index files, and no listings
# Needs: mod_dir; AllowOverride FileInfo Indexes Options=Indexes
ErrorDocument 403 /errors/403.html
DirectoryIndex index.php index.html
Options -Indexes
Output
/files/     403  <!doctype html> <title>Forbidden</
/docs/      200  docs/index.php 
/docs/old/  403  <!doctype html> <title>Forbidden</
/files      301  <!DOCTYPE HTML PUBLIC "-//W3C//DTD

Each line is a URL, its status and the first body bytes. /files/ gets the custom 403. /docs/ holds both index files and serves index.php. /docs/old/ holds only index.htm: a DirectoryIndex in .htaccess replaces the inherited list. /files got a 301 to the slashed form from DirectorySlash; leave it on. Without the Indexes class, line 4 gave a 500.

Keep the minus sign in Options -Indexes: a bare Options Indexes replaces the inherited set and drops FollowSymLinks, which mod_rewrite needs (URL Rewriting with mod_rewrite).