Protect Non-Web Accessible Directories
It is a good idea to protect non-Web accessible directories: directories or files in those directories not meant to accessed via the web. These directories can also include templates directories, directories which include files which are included or required by other files, etc. Simply create a .htaccess file (or edit existing .htaccess file), and add the following lines:

order allow,deny
deny from all

These lines protect the directory by telling the server to deny access to everyone. No one, including admins, can access the directory using a web browser or other web device. Do not apply for web accessible directories including images, styles, and javascripts directories.

Last Revised: 2015-08-28 23:16:57

