.htaccess generator
Generate an Apache .htaccess file: force HTTPS, strip or add www, SPA fallback, 301/302 redirects, cache headers, gzip, security headers, basic auth, custom error pages and User-Agent / IP blocking.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Requirements
Notes
.htaccess
Save it as .htaccess in the site root; check the response headers with curl -I afterwards.
# 由 UniKit 生成:Apache .htaccess
# 需要 mod_rewrite / mod_headers / mod_deflate / mod_expires / mod_auth_basic 模块支持
<IfModule mod_rewrite.c>
RewriteEngine On
# 强制 HTTPS
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
# 去掉 www
RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
RewriteRule ^ https://%1%{REQUEST_URI} [L,R=301]
# SPA 回退:真实文件与目录直接返回,其余交给 index.html
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^ index.html [L]
</IfModule>
# 静态资源缓存
<IfModule mod_expires.c>
ExpiresActive On
ExpiresByType text/css "access plus 30 days"
ExpiresByType application/javascript "access plus 30 days"
ExpiresByType image/png "access plus 30 days"
ExpiresByType image/jpeg "access plus 30 days"
ExpiresByType image/svg+xml "access plus 30 days"
ExpiresByType font/woff2 "access plus 30 days"
</IfModule>
<IfModule mod_headers.c>
<FilesMatch "\.(css|js|mjs|png|jpe?g|gif|webp|avif|svg|ico|woff2?|ttf)$">
Header set Cache-Control "public, max-age=2592000, immutable"
</FilesMatch>
</IfModule>
# gzip 压缩
<IfModule mod_deflate.c>
AddOutputFilterByType DEFLATE text/html text/plain text/css text/xml application/javascript application/json application/xml image/svg+xml
</IfModule>
# 安全响应头
<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" env=HTTPS
</IfModule>
# 自定义错误页
ErrorDocument 404 /404.html
Statistics
3551What this tool does
- Pin a static site to one canonical address: force HTTPS and strip www with two RewriteCond + RewriteRule pairs so the same page stops living at several URLs.
- Serve a client-side router (Vue Router, React Router) with the history fallback, so opening /user/1 directly returns index.html instead of a 404.
- Migrate a site with 301s: list the old paths and their new targets once and let search engines carry the ranking across.
- Add caching, compression and security headers: Cache-Control plus Expires for assets, gzip for text types, and nosniff, X-Frame-Options and HSTS.
- Protect a preview or admin area with basic auth plus Require valid-user, and block noisy User-Agents and IP ranges without extra modules.
Example
Input
Force HTTPS, strip www, SPA fallback, custom 404 page at /404.html (caching, gzip and security headers off)
Output
# 由 UniKit 生成:Apache .htaccess
# 需要 mod_rewrite / mod_headers / mod_deflate / mod_expires / mod_auth_basic 模块支持
<IfModule mod_rewrite.c>
RewriteEngine On
# 强制 HTTPS
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
# 去掉 www
RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
RewriteRule ^ https://%1%{REQUEST_URI} [L,R=301]
# SPA 回退:真实文件与目录直接返回,其余交给 index.html
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^ index.html [L]
</IfModule>
# 自定义错误页
ErrorDocument 404 /404.htmlRedirects come before the SPA fallback, otherwise index.html swallows every path; the www rule follows whether HTTPS forcing is on when it picks the scheme.
Frequently asked questions
Which folder does .htaccess belong in?
The document root, and Apache must allow it via AllowOverride All. You can drop another copy in a subdirectory — the directives stack — but first confirm mod_rewrite is enabled.
Why are HTTPS and www two separate rules?
They test different things: %{HTTPS} for the scheme and %{HTTP_HOST} for the leading www.. With both enabled they run in order and land on a single address, so users never sit on http://www as an intermediate hop.
Do the SPA fallback and redirect rules conflict?
No, but order matters. The redirect rules are emitted before the fallback, so only paths that match no redirect and are not real files or directories reach index.html. Reversed, the fallback would swallow every redirect.
Which syntax is used to block IPs?
The Apache 2.4 <RequireAll> form: Require all granted first, then one Require not ip 203.0.113.5 or Require not ip 198.51.100.0/24 per entry. The old 2.2 Order deny,allow syntax is no longer recommended.
Where does the .htpasswd file come from?
AuthUserFile points at a password file you create with htpasswd -c /var/www/.htpasswd username. Keep it outside the document root, otherwise it can be downloaded directly.
Keywords:htaccessapacheredirectrewrite rulebasic authhtaccess 生成Apache 配置重定向伪静态密码保护