WordPress新建文件及文件夹权限异常问题咨询
Let's break down why this is happening and how to fix it—this is almost always tied to your system's umask setting (which controls default permissions for new files/folders) plus ensuring your web server can access the resources.
Why You're Getting 403 Forbidden Errors
Your current umask is set to 007, which calculates default permissions like this:
- New files:
666 - 007 = 660(only the owner and their group have read/write access; all other users get nothing) - New folders:
777 - 007 = 770(only the owner and their group have full access; others get nothing)
Web servers (like Apache or Nginx) run under a dedicated user (usually www-data), which is likely not part of your personal user group. Since "other" users have no access to these files/folders, the server can't load them—hence the 403 errors in your JavaScript console.
Solutions to Fix Default Permissions
1. Temporary Umask Adjustment (Current Session Only)
Quickly test if this resolves the issue by running this in your terminal:
umask 022
Now create a new file or folder—you’ll see permissions switch to 644 (files) and 755 (folders), which lets the web server read them. This change only lasts until you close the terminal.
2. Permanent Umask Setup (User or Global Level)
To make the fix stick:
- For your user only: Open your shell config file (e.g.,
~/.bashrcor~/.zshrc) and add this line at the end:
Save the file, then runumask 022source ~/.bashrcto apply changes right away. - For all users system-wide: Edit
/etc/profileor/etc/bash.bashrc(you’ll need sudo privileges) and add the sameumask 022line.
3. Add Web Server User to Your Group (Alternative Fix)
If you want to keep 660/770 permissions but let the server access the files, add the web server user to your personal group:
sudo usermod -aG your_username www-data
Replace your_username with your actual Linux username. Then restart your web server to apply the change:
# For Apache sudo systemctl restart apache2 # For Nginx sudo systemctl restart nginx
Now the web server user is part of your group, so it can access the 660/770 permissioned files.
4. Use ACLs for Granular Default Permissions (Advanced)
If you need custom default permissions for a specific directory (like your website root), use Access Control Lists (ACLs):
sudo setfacl -d -m u::rwx,g::rwx,o::rx /path/to/your/webroot
This sets default rules so any new file/folder in that directory inherits:
- Owner: full read/write/execute access
- Group: full read/write/execute access
- Others: read/execute access
Most modern filesystems (like ext4) support ACLs by default—if yours doesn’t, you’ll need to remount the drive with the acl option.
内容的提问来源于stack exchange,提问作者Bálint Budavölgyi

