Web Technician Online
Home / Guides / 403 Forbidden: check access before changing permissions

403 Forbidden: check access before changing permissions

Find out why access is refused without opening up your entire website.

What it means

The server understood the request but refused access. Signing in again does not necessarily fix it; the refusal may come from a permission or security rule.

Safe checks first

Verify the URL and whether the affected resource should be public. Compare a public page with the failing page. If an account is required, confirm that the account has the correct role.

Identify the blocking layer

Check the hosting access log, security-plugin events and CDN or firewall events at the same timestamp. A directory URL may have no index document while directory listing is intentionally disabled.

Fix the specific rule

Review the rule or permission responsible with your host’s documented settings. Back up configuration before editing it. Do not use blanket 777 permissions, disable the whole firewall, or expose a private folder to fix a single request.

When to ask your provider

If a hosting or CDN rule is responsible, supply the failing URL, timestamp and request identifier. Ask for a targeted change and recheck that private resources remain protected.

Reference

Official technical documentation