cPanelOps · Hosting guides for site operators
cPanelOpsv2.2.0
Plain-English cPanel help from the team behind FirstResponderHost
26 guides live
CpanelOps / PageOps

Home › Guides

Security

Password-protect an admin folder with Directory Privacy

A two-minute way to put a login in front of a dashboard, a staging copy or any folder that is not meant for the public.

Small sites collect folders that were never meant for visitors: an admin dashboard, an internal tool, a staging copy, a folder of reports. If the address can be guessed or is linked anywhere, anyone can open it, and search engines can find it. cPanel has a built-in way to put a username and password in front of a folder without writing any code.

Set it up

  1. In cPanel, open Directory Privacy (in the Files section).
  2. Browse to the folder and click Edit beside it.
  3. Tick Password protect this directory, give it a name (this text appears in the login prompt), and save.
  4. On the same page, create a user: type a username and a strong password and save.

From then on the browser asks for that login before showing anything in the folder or in any folder beneath it.

What it does behind the scenes

cPanel writes a few lines into an .htaccess file in that folder and stores the usernames, with the passwords scrambled, in a file kept outside your public web space. The check is done by the web server itself, before any page or script in the folder runs. That makes it a useful outer gate even for a tool that has its own login: an attacker cannot reach the tool's login form at all without the first password.

Things to know before relying on it

  • Use it over HTTPS only. This kind of login sends the password with every request. Over plain HTTP it can be read in transit.
  • It protects the folder, not copies elsewhere. If the same files are reachable through another address, that address is still open.
  • Public pages cannot quietly use files inside it. If a public page loads a script, image or data feed from the protected folder, visitors will get a login prompt. Move the shared files out, or protect a narrower folder.
  • There is no lockout. The server will accept guesses all day, so the password must be long and not used anywhere else.
  • Do not protect the whole site if you use AutoSSL. Certificate renewal needs to reach /.well-known/ without a login.

Allowing only your own address instead

If you always work from one fixed internet address, you can skip the password and let only that address in. Put this in an .htaccess file in the folder, with your own address in place of the example:

Require ip 203.0.113.5

Everyone else gets 403 Forbidden. Home connections often change address, so this suits an office line better than a phone.

Keep it out of search results too

A password stops people opening the folder, and it also stops search engines reading it. If the folder was public before, its pages may already be listed. They drop out on their own once crawlers start getting the login prompt, and you can ask for faster removal in the search engine's webmaster tools.

Removing protection

Go back to Directory Privacy, open the folder, and untick the box. The users you created stay saved in case you switch it on again.

Common questions

Can several people have their own logins?

Yes. Add a user for each person on the same Directory Privacy page. When someone leaves, delete their user and nobody else has to change a password.

How do I sign out?

This kind of login has no sign-out button. The browser remembers the details until it is fully closed, so on a shared computer use a private window and close it when you finish.

Will this stop search engines listing the folder?

They cannot read anything inside it, so nothing new gets indexed. Addresses that were indexed while the folder was open disappear over the following weeks. Do not also block the folder in robots.txt; that only advertises the path.

Does it work for a single file?

Directory Privacy protects folders. To cover one file, either move it into a protected folder or wrap the same rules in a <Files "name.html"> block in .htaccess.

Spotted a mistake, or a step that has changed?

cPanel's screens differ a little between versions and hosts. Tell us at info@firstresponderhost.com and we will correct the guide.

More guides