在WordPress中嵌入MP3仅允许播放禁止下载,.htaccess规则求助
Fixing Audio Playback Issues with .htaccess Referer Rules in WordPress
Hey there, let's troubleshoot why your audio files stopped playing after adding those .htaccess rules. The core problem is that your original rules are too strict and miss key edge cases that WordPress and modern browsers rely on. Here's what's going wrong and how to fix it:
What's Wrong with Your Original Rules?
Your current rules don't account for:
- HTTP/HTTPS and www variations: If your site uses
https://orwww.mysite.net.ltd, the referer header won't match your rule (you omitted the protocol and www wildcard). - WordPress admin access: When previewing or editing audio in the WP backend, the referer will be your site's
/wp-admin/path, which your rules block. - Proper domain path matching: Your rules don't include a trailing slash, so they might not match subpages where audio is embedded.
Corrected .htaccess Rules
Replace your existing rules with this adjusted version:
RewriteEngine On # Block direct access to audio files unless request comes from your site RewriteCond %{HTTP_REFERER} !^https?://(www\.)?mysite\.net\.ltd/ [NC] RewriteCond %{HTTP_REFERER} !^https?://(www\.)?mysite\.net\.ltd/.*$ [NC] # Allow access from WordPress admin (for editing/previews) RewriteCond %{HTTP_REFERER} !^https?://(www\.)?mysite\.net\.ltd/wp-admin/ [NC] # Apply the block to audio file types RewriteRule \.(mp3|m4a|ogg|wav)$ - [F]
Breakdown of the Fixes:
https?://: Matches both HTTP and HTTPS versions of your site(www\.)?: Accounts for both www and non-www domain variations- Trailing
/: Ensures we match your domain root and all subpages where audio might be embedded - The wp-admin rule lets you work with audio files in the WordPress backend without getting blocked
Post-Fix Steps:
- Clear your browser cache: Old cached audio requests might still be blocked, so a hard refresh (Ctrl+Shift+R) is necessary.
- Test frontend playback: Load a page with embedded audio and confirm it plays correctly.
- Verify direct access is blocked: Try opening the audio file's direct URL in a new tab—you should see a 403 Forbidden error (this means your anti-download rule is working).
If You Still Have Issues:
Some modern browsers or privacy extensions strip the Referer header for same-origin requests. If this happens, you might need a more robust solution like:
- Using a PHP wrapper script to serve audio files (checks if the request originates from your site before sending the file)
- Adding a
Referrer-Policyheader to your site to ensure referer data is sent consistently (you can add this via your theme'sfunctions.phpor a security plugin)
内容的提问来源于stack exchange,提问作者sajad saadat
相关产品推荐
相关产品推荐

