# Hostinger/LiteSpeed: what .htaccess to use? Getting 403 error after fresh install

**URL:** <https://forum.mautic.org/t/hostinger-litespeed-what-htaccess-to-use-getting-403-error-after-fresh-install/34002>\
**Category:** Mautic 5 Install/Upgrade Support\
**Created:** [October 31, 2024, 4:46pm UTC](https://forum.mautic.org/t/hostinger-litespeed-what-htaccess-to-use-getting-403-error-after-fresh-install/34002 "2024-10-31T16:46:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ctotech](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ctotech/32/13067_2.png) [@ctotech](https://forum.mautic.org/u/ctotech)\
**Post date:** [October 31, 2024, 4:46pm UTC](https://forum.mautic.org/t/hostinger-litespeed-what-htaccess-to-use-getting-403-error-after-fresh-install/34002/1 "2024-10-31T16:46:01Z")

</div>

**Your software**  
My Mautic version is: 5.04  
My PHP version is: 8.2  
My Database type and version is: MySQL 5

**Your problem**  
My problem is:

- after fresh install of Mautic on [Hostinger.com](http://Hostinger.com) (a LiteSpeed server), I am getting 403 server error when I try to continue installation.

These errors are showing in the log:

Steps I have tried to fix the problem:

- I have commented-out the following section in .htaccess file, which allowed me to finish installation:

`<IfModule authz_core_module>`

- But then files like ie. `/config/local.php` are no longer restricted from access in browser.

- What should I use for .htaccess on a LiteSpeed server to protect the internale files?

- ChatGPT rewrote the .htaccess as the following, will this be sufficient?

```auto
# Use the front controller as index file
DirectoryIndex index.php

# Set Authorization header for OAuth2 for when PHP is running under fcgi
RewriteCond %{HTTP:Authorization} .+
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]

# Redirect to URI without front controller to prevent duplicate content
RewriteCond %{REQUEST_URI} ^/index\.php(/(.*)|$)
RewriteRule ^index\.php(/(.*)|$) /$2 [R=301,L]

# If the requested filename exists, simply serve it.
RewriteCond %{REQUEST_FILENAME} -f
RewriteRule . - [L]

# Rewrite all other queries to the front controller.
RewriteRule . /index.php [L]

# Deny access to PHP files directly
<FilesMatch "\.php$">
    Order Allow,Deny
    Deny from all
</FilesMatch>

# Deny access to composer files
<FilesMatch "^(composer\.json|composer\.lock)$">
    Order Allow,Deny
    Deny from all
</FilesMatch>

# Allow access to specific files
<FilesMatch "^(index\.php|upgrade/upgrade\.php)$">
    Order Allow,Deny
    Allow from all
</FilesMatch>

# Compression settings (LiteSpeed handles this natively)
<IfModule mod_deflate.c>
    AddOutputFilterByType DEFLATE application/javascript
    AddOutputFilterByType DEFLATE application/rss+xml
    AddOutputFilterByType DEFLATE application/x-font-ttf
    AddOutputFilterByType DEFLATE text/css
    # Other types can be added here
</IfModule>

```

---

<div class="post-metadata">

**Author:** ![marcus42](https://avatars.discourse-cdn.com/v4/letter/m/ac91a4/32.png) [@marcus42](https://forum.mautic.org/u/marcus42)\
**Post date:** [November 8, 2024, 3:37pm UTC](https://forum.mautic.org/t/hostinger-litespeed-what-htaccess-to-use-getting-403-error-after-fresh-install/34002/2 "2024-11-08T15:37:30Z")

</div>

A 403 Forbidden error is usually a result of a web server restriction.

You need to look into rules like the `Order Allow,Deny` within the `<FilesMatch "\.php$">` found in your `.htaccess`.

Also check your files&folders permissions, litespeed configuration et al.
