Skip to content

feat(nginx-proxy): Add wildcard HTTP auth support for WordPress multisite - #298

Merged
mrrobot47 merged 6 commits into
EasyEngine:developfrom
mrrobot47:feat/http-auth
Jan 8, 2026
Merged

mrrobot47 merged 6 commits into
EasyEngine:developfrom
mrrobot47:feat/http-auth

Conversation

@mrrobot47

Copy link
Copy Markdown
Member

Summary

Adds wildcard htpasswd file support to enable HTTP basic authentication across WordPress multisite domains using a single htpasswd file.

Features

  • Wildcard naming convention: _wildcard.domain.com applies HTTP auth to domain.com AND all subdomains (*.domain.com)
  • Multi-level TLD support: Works with .co.in, .com.au, and other multi-level TLDs
  • Cascading lookup: Checks exact match → wildcard → default

Lookup Logic

Host Wildcard File Checked
blog.domain.co.in (4 parts) _wildcard.domain.co.in → _wildcard.co.in → default
domain.co.in (3 parts) _wildcard.co.in → default
blog.example.com (3 parts) _wildcard.example.com → default
example.com (2 parts) _wildcard.example.com → default

Fix bug where blog.example.com incorrectly checked for
_wildcard.blog.example.com instead of _wildcard.example.com.
Changes:
- 4+ part domains: check 3-part wildcard first, then 2-part fallback
- 2-3 part domains: check 2-part wildcard directly
- Fixed template formatting to match original style
- Updated README with corrected lookup table
Copilot AI review requested due to automatic review settings January 8, 2026 05:12
@mrrobot47
mrrobot47 merged commit 409962c into EasyEngine:develop Jan 8, 2026
19 of 20 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request adds wildcard HTTP basic authentication support specifically designed for WordPress multisite subdomain configurations. It enables a single _wildcard.domain.com htpasswd file to protect both the main domain and all its subdomains.

Key changes:

  • Implements cascading wildcard htpasswd lookup logic with support for multi-level TLDs (e.g., .co.in, .com.au)
  • Adds comprehensive documentation explaining the wildcard naming convention and lookup order
  • Includes cleanup of trailing whitespace in unrelated parts of the template

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
nginx-proxy/nginx.tmpl Implements wildcard htpasswd lookup with cascading logic for 2-4+ part domain names, replacing simple default fallback
nginx-proxy/README.md Adds new README with detailed documentation of HTTP auth features, wildcard naming conventions, lookup order, and usage examples

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread nginx-proxy/nginx.tmpl
Comment thread nginx-proxy/nginx.tmpl
mrrobot47 added a commit that referenced this pull request Sep 25, 2026
The wildcard lookup counted labels on the host instead of matching the site, so a subsite of a 4+ label subdomain multisite (*.ms.dev.example.com) never found _wildcard.ms.dev.example.com, while an unrelated site like shop.example.com picked up _wildcard.example.com and demanded another site's credentials.

A _wildcard.X file now applies only to a host that is literally *.X; every other host uses its exact file or falls back to default. The ACL include uses the same mapping (vhost.d/_wildcard.X_acl for *.X hosts), including the mailhog and /ee-admin/ locations, so per-site IP whitelists also apply to subdomain hosts.

BREAKING CHANGE: _wildcard.X now applies only to the literal *.X host, no longer to X itself, which needs its own exact htpasswd/X (and vhost.d/X_acl) file. The label-counting fallback from #298 (checking _wildcard.<last 3 labels>, then _wildcard.<last 2 labels>, for multi-level TLDs) is gone, so setups that relied on it to protect other hosts must add exact files for them.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants