13.8  Protecting System Settings

To run a really tight ship, you’ll want to stop users from setting up .htaccess files which can override security features you’ve configured. Here’s one way to do it.

In the server configuration file, put

<Directory />
AllowOverride None

This prevents the use of .htaccess files in all directories apart from those specifically enabled.

