When accessing the Magento administration console, you may encounter the error:
Your web server is configured incorrectly. As a result, configuration files with sensitive information are accessible from the outside. Please contact your hosting provider.
This error indicates a security misconfiguration in your Magento installation.
Cause
-
File permissions are set too permissively, allowing external access to sensitive configuration files.
-
The
.htaccessfile in theappsubdirectory is missing or misconfigured.
Resolution Steps
Step 1: Verify .htaccess File
-
Log in to your hosting account via SSH or File Manager.
-
Navigate to the
appsubdirectory of your Magento installation. -
Confirm that a
.htaccessfile exists. -
If missing, create a new
.htaccessfile with the following directives:apacheOrder deny,allow Deny from all
Step 2: Correct File Permissions
-
Directories should be set to
755(owner read/write/execute, group/world read/execute). -
Files should be set to
644(owner read/write, group/world read).
You can reset permissions using SSH:
Bash
# Set file permissions
find . -type f -exec chmod 644 {} \;
# Set directory permissions
find . -type d -exec chmod 755 {} \;
Step 3: Clear Magento Cache
After fixing permissions and .htaccess, clear Magento’s cache:
Bash
php bin/magento cache:flush
Important Notes
-
Always back up your site before making configuration changes.
-
Incorrect permissions may break functionality if set too restrictively.
-
If you are on ruachost.com shared hosting, contact support to confirm server‑level security settings.