.htaccess คืออะไร ทำงานยังไง?
ไฟล์ .htaccess (Hypertext Access) เป็นไฟล์ Configuration ของ Apache Web Server ที่อนุญาตให้ตั้งค่าพฤติกรรมของ Server ในระดับ Directory โดยไม่ต้องแก้ไข Server Configuration หลัก ชื่อไฟล์ขึ้นต้นด้วยจุดทำให้เป็น Hidden File บน Linux
ไฟล์ .htaccess ทำงานโดย Apache จะอ่านไฟล์นี้ในทุก Directory ที่ Request ผ่าน ทำให้ตั้งค่าได้ต่างกันในแต่ละ Folder สิ่งสำคัญที่ต้องรู้:
- ทำงานเฉพาะบน Apache Web Server (ไม่ใช่ Nginx)
- ต้องมี
AllowOverride Allในการตั้งค่า Server จึงจะทำงาน - ผลกระทบ Performance เล็กน้อยเพราะ Apache ต้องอ่านทุก Request
- Syntax ผิดแม้แต่ 1 ตัวทำให้เกิด 500 Error
คำสั่งพื้นฐาน
# ปิด Directory Listing
Options -Indexes
# กำหนดไฟล์หลักของเว็บ
DirectoryIndex index.php index.html
# กำหนด Error Page
ErrorDocument 404 /404.html
ErrorDocument 403 /403.html
ErrorDocument 500 /500.html
# กำหนด Character Encoding
AddDefaultCharset UTF-8
Redirect (301 และ 302)
ใช้สำหรับ Redirect URL เก่าไปยัง URL ใหม่:
# 301 Permanent Redirect (SEO-friendly)
Redirect 301 /old-page.html https://yoursite.com/new-page.html
# 302 Temporary Redirect
Redirect 302 /promo https://yoursite.com/sale
# Redirect ทั้งโดเมนไปยังโดเมนใหม่
Redirect 301 / https://newdomain.com/
# Redirect ทุก .html ไปยัง ไม่มี .html
Redirect 301 /about.html https://yoursite.com/about
RewriteRule และ RewriteCond
RewriteRule ใช้ Regular Expression เพื่อแปลง URL เป็นรูปแบบอื่น ต้องเปิด RewriteEngine ก่อนเสมอ:
RewriteEngine On
# Force HTTPS
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
# ลบ .php Extension ออกจาก URL (Pretty URL)
RewriteCond %{REQUEST_FILENAME} !-d
RewriteCond %{REQUEST_FILENAME}.php -f
RewriteRule ^([^\.]+)$ $1.php [NC,L]
# WordPress Permalink
RewriteBase /
RewriteRule ^index\.php$ - [L]
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule . /index.php [L]
Flag ที่ใช้บ่อย:
[L]— Last Rule หยุดประมวลผล Rule ถัดไป[R=301]— Redirect ด้วย Status Code 301[NC]— Case Insensitive[F]— Forbidden (403)[NE]— NoEscape ไม่ Encode Special Characters
ปกป้องไฟล์และ Directory
# ป้องกันไม่ให้อ่าน wp-config.php
<Files wp-config.php>
Order Allow,Deny
Deny from All
</Files>
# ป้องกัน Directory ด้วย Password
AuthType Basic
AuthName "Restricted"
AuthUserFile /home/user/.htpasswd
Require valid-user
# Block IP เฉพาะ
Order Allow,Deny
Allow from All
Deny from 192.168.1.100
# ป้องกันไม่ให้รัน PHP ใน Upload Directory
<Directory /home/user/public_html/wp-content/uploads>
php_flag engine off
</Directory>
กำหนดค่า PHP ผ่าน .htaccess
# เพิ่ม Memory
php_value memory_limit 256M
php_value max_execution_time 120
php_value upload_max_filesize 32M
php_value post_max_size 32M
# เปิด/ปิด Error Display
php_flag display_errors Off
php_flag log_errors On
ตรวจสอบ Syntax
ก่อน Upload ไฟล์ .htaccess ควรตรวจ Syntax ก่อนเพื่อป้องกัน 500 Error:
# ตรวจสอบ Syntax ผ่าน Apache (ต้องมี SSH)
apachectl -t
# หรือ
httpd -t
# ทดสอบ Rewrite ด้วย curl
curl -I http://yoursite.com/old-page
ตรวจสอบว่า .htaccess ทำงานถูกต้อง
# ตรวจสอบว่า Redirect ทำงาน
curl -I http://yoursite.com/old-url
# ตรวจสอบ RewriteRule ด้วย mod_rewrite log (ต้อง Enable ก่อน)
# เพิ่มใน .htaccess: LogLevel alert rewrite:trace3
# ดู Error Log เมื่อเกิด 500
tail -50 /home/user/public_html/error_log
# ตรวจสอบว่า .htaccess ถูกอ่านโดย Apache
curl -I https://yoursite.com/ | grep -i "x-"
# แล้วทดสอบทีละ Rule เพื่อหาสาเหตุ อย่าพยายามแก้หลาย Rule พร้อมกันแก้ปัญหาที่พบบ่อย
Error: "500 Internal Server Error" หลังแก้ .htaccess
สาเหตุที่พบบ่อยที่สุดคือ Syntax ผิด ให้ Comment Rules ทั้งหมดออกก่อน (# นำหน้าทุกบรรทัด) แล้วค่อยเปิดทีละ Section จนพบ Rule ที่ทำให้เกิด Error ตรวจสอบ Error Log ด้วยเพราะมักระบุบรรทัดที่มีปัญหา
Error: RewriteRule ไม่ทำงานทั้งที่ Syntax ถูก
ตรวจสอบว่า mod_rewrite ถูก Enable บน Server (a2enmod rewrite บน Ubuntu) และ AllowOverride ตั้งเป็น All ใน Apache Config ถ้าเป็น Shared Hosting ให้ติดต่อ Support เพื่อยืนยัน
Error: .htaccess ที่สร้างผ่าน Notepad มีปัญหา
ไฟล์ที่แก้ด้วย Windows Notepad อาจมี BOM (Byte Order Mark) หรือ CRLF Line Ending ซึ่งทำให้ Apache อ่านผิด ให้ใช้ Editor ที่รองรับ Unix Line Ending เช่น Notepad++, VS Code หรือแก้ผ่าน cPanel File Manager โดยตรง
Error: Password Protection ผ่าน .htpasswd ไม่ทำงาน
ตรวจสอบว่า Path ใน AuthUserFile เป็น Absolute Path ที่ถูกต้อง (ไม่ใช่ /public_html/) และไฟล์ .htpasswd อยู่นอก Web Root เพื่อความปลอดภัย สร้าง .htpasswd ผ่านคำสั่ง htpasswd -c /home/user/.htpasswd username
คำถามที่พบบ่อย
.htaccess กับ nginx.conf ต่างกันอย่างไร?
.htaccess ใช้กับ Apache Web Server เท่านั้น ทำงานระดับ Directory Nginx ไม่รองรับ .htaccess แต่ใช้ nginx.conf แทน ซึ่งต้องแก้โดย Admin เท่านั้น ถ้า Hosting ใช้ Nginx ต้องขอ Support ช่วยตั้งค่า
มีหลาย .htaccess ในหลาย Directory ได้ไหม?
ได้ Apache อ่าน .htaccess จากทุก Directory ในเส้นทางของ Request ค่าที่ตั้งใน Directory ลึกกว่าจะ Override ค่าจาก Directory บน นิยมใช้เพื่อตั้งค่าพิเศษสำหรับบาง Subdirectory โดยไม่กระทบทั้งเว็บ
ควรเก็บ .htaccess Backup ไว้ไหม?
ควรมากเพราะ .htaccess ที่ผิดทำให้เว็บล่มทันที เก็บ Backup ทุกครั้งก่อนแก้ไข ตั้งชื่อเช่น htaccess-backup-2026.txt เก็บไว้นอก Web Root หรือในระบบ Version Control