WordPress上传文件后.htaccess的deny from all规则失效求助
Hey there, let's break down why your current .htaccess setup is only blocking FTP-uploaded files, and walk through the fixes to lock down all content in wp-content/uploads/ for good.
Possible Causes
- Missing .htaccess in auto-generated subdirectories: WordPress automatically creates year/month subdirectories (like
wp-content/uploads/2024/05) when you upload files via the WP dashboard. If you only added.htaccessto existing subdirectories, these dynamically created folders won't have thedeny from allrule, so their files remain accessible. - Root .htaccess rules overriding subdirectory settings: If your site's root
.htaccesshas rewrite rules that explicitly allow access towp-content/uploads/(common with caching plugins or custom setups), Apache will prioritize those rules and skip executing the subdirectory.htaccessfiles entirely. - Apache AllowOverride restrictions (less likely): If your server's Apache config sets
AllowOverride Nonefor thewp-content/uploads/directory, subdirectory.htaccessfiles are ignored. But since FTP-uploaded files are blocked, this is probably not the issue.
Fixes to Try
1. Add a Global Rule to Root .htaccess (Recommended)
Instead of manually adding .htaccess to every subdirectory, set a single rule in your site's root .htaccess that blocks all access to wp-content/uploads/—this covers both existing and future auto-generated folders.
For Apache 2.2 and older:
<Directory "/full/path/to/your/wp-content/uploads"> Deny from all </Directory>
For Apache 2.4+ (most modern servers):
<Directory "/full/path/to/your/wp-content/uploads"> Require all denied </Directory>
If you prefer using rewrite rules instead (avoids editing Directory blocks):
RewriteRule ^wp-content/uploads/.*$ - [F,L]
This returns a 403 Forbidden response for any request to files or folders in uploads/.
2. Auto-Generate .htaccess in New WP Upload Directories
If you want to stick with per-subdirectory .htaccess files, add this code to your active theme's functions.php file. It will automatically create a .htaccess with the block rule whenever WordPress makes a new upload subdirectory:
add_action('wp_mkdir_p', 'auto_add_uploads_htaccess'); function auto_add_uploads_htaccess($dir) { $uploads_dir = wp_upload_dir(); $uploads_base = $uploads_dir['basedir']; // Only target directories inside the main uploads folder if (strpos($dir, $uploads_base) === 0) { $htaccess_path = $dir . '/.htaccess'; if (!file_exists($htaccess_path)) { // Use "Require all denied" instead if you're on Apache 2.4+ file_put_contents($htaccess_path, 'deny from all'); // Set secure file permissions chmod($htaccess_path, 0644); } } }
3. Check for Conflicting Root .htaccess Rules
Open your root .htaccess and look for rules like this:
RewriteRule ^wp-content/uploads/ - [L]
The [L] flag tells Apache to stop processing further rules once this one runs, which means your subdirectory .htaccess blocks never get applied. If you find this rule, either delete it or move your upload-blocking rule above it in the file.
After making any changes, clear your browser cache and test accessing a WordPress-uploaded file—you should get a 403 Forbidden error now.
内容的提问来源于stack exchange,提问作者alex3410

