6.29. Mixing Read-Only and Write Access to a Subversion Repository
Problem
You want to protect different portions of your Subversion repository differently, allowing read-access in some paths and write-access in others.
Solution
For a simple solution, you can use the <LimitExcept> to protect certain files or paths such that write access requires authentication:
<Location "/repos">
DAV svn
SVNParentPath "/repository/subversion"
AuthType Basic
AuthName "Log in for write access"
AuthUserFile "/path/to/authfile"
<LimitExcept GET REPORT OPTIONS PROPFIND>
Requre valid-user
</LimitExcept>
</Location>The configuration fragment above applies the restriction to the entire Subversion repository. For more flexible or fine-grained control, combine this with the mod_authz_svn module:
LoadModule authz_svn_module modules/mod_authz_svn.so
<Location "/repos">
DAV svn
SVNParentPath "/repository/subversion"
Order Deny,Allow
Allow from all
AuthName "Log in for write access"
AuthType Digest
AuthDigestDomain "/repos/"
AuthDigestFile "/path/to/digest-file"
AuthzSVNAccessFile "/path/to/access-file"
<Limit GET PROPFIND OPTIONS REPORT>
Satisfy Any
</Limit>
<LimitExcept GET PROPFIND OPTIONS REPORT>
Satisfy All
Require valid-user
</LimitExcept>
</Location>Discussion
The first solution takes a simple approach: it says, in essence, “These methods are harmless, but if you use any others you gotta log in.”
The second solution combines this with the functionality of the mod_authz_svn module, which allows you to grant (or ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access