Django + apache2 error: [Errno 13] Permission denied: '/photos'

Viewed 47

I have a ubuntu server hosting my application, which consists of a front-end made with angular, and an API made with django.

When I try to upload images through the API, I get the error: [Errno 13] Permission denied: '/photos'

I tried setting permissions to 644/755, full read & write permissions to the directory, I also tried creating groups and giving www-data control to the directory...but nothing worked so far.

I'm using Apache2 with mod_wsgi to serve my django app. Here is the folders structure:

/var/www/html/api
│   manage.py
│   passenger.wsgi
│   requirements.txt 
│
│───photos (this is the related directory)
│
└───apiX
│   │   serializers.py
│   │   views.py
│   │   ........
│   │
└───apiMain
    │   asgi.py
    │   settings.py
    │   wsgi.py

Here is my /etc/apache2/apache2.conf settings:

# Django app config!
WSGIScriptAlias /api /var/www/html/api/apiMain/wsgi.py

WSGIPythonHome /var/www/html/api/venv

WSGIPythonPath /var/www/html/api/venv/lib64/python3.8/site-packages

WSGIDaemonProcess x_api python-home=/var/www/html/api/venv python-path=/var/www/html/api
WSGIProcessGroup x_api

<Directory /var/www/html/api>

<Files apiMain/wsgi.py>

Require all granted

</Files>

</Directory>

Alias /photos/ /var/www/html/api/photos
Alias /photos /var/www/html/api/photos
<Directory /var/www/html/api/photos>

Require all granted

</Directory>

Thank you!

1 Answers

Apache service needs read permission the whole path to the target directory/files, so you need to provide such rights to Apache user.

To simulate user writes you can inpersonate and simulate the user (I would assume the apache service is named www-data):

sudo -u www-data ls -al /var/www/html/api/photos

If you get Permission denied then you need to check folder by folder:

sudo -u www-data ls -al /var/
sudo -u www-data ls -al /var/www/
sudo -u www-data ls -al /var/www/html/
sudo -u www-data ls -al /var/www/html/api/
sudo -u www-data ls -al /var/www/html/api/photos

whichever folder is missing read rights, then setup correct permissions, for instance:

chmod o+r /var/www/html ...

(or chgrp www-data /var/www... + chmod g+r ...)

But there is an issue with security - is it secure to allow such user rights for all users? Sometimes it is better solution to put folders less deep in system, e.g. put photos and setup permissions in:

/srv/photos
Related