Sorry, don't forget to add the auth to php block too or anyone can bypass the auth when accessing php files Posted at Nginx Forum: http://forum.nginx.org/read.php?2,4151,4185#msg-4185