Direct Access Blocker

Component ID

1690532

Component name

Direct Access Blocker

Component type

module

Maintenance status

Development status

Component security advisory coverage

not-covered

Component created

Component changed

Component body

What Does The Module Do?

This module enables site administrators to:

  • Block direct access to specific paths, for example user/register
  • Specify the paths that should be blocked
  • Specify the action that should be taken when a request is blocked...
    • 403 (access denied) - the default action
    • Redirect to specified URL, for example a page explaining why access was denied

Important Security Note

The module prevents access when there is no http referer sent by the http client (browser, robot, etc). For this reason this block can be circumvented and is not fool proof but will help prevent a percentage of automated spam attacks that don't spoof http referer.

In addition it's advisable to do this kind of blocking using .htaccess. This module only exists for administrators who wish to control the direct access blocking via Drupal's admin so it's easy to manage.