Fix the PHP "open_basedir restriction in effect" error on LWS Panel

Procédure

  

Service concerned : shared web hosting LWS Panel
Concerned panel : LWS Panel
Level : intermediate

The error open_basedir restriction in effect appears when a PHP script tries to access a file or folder located outside the space authorized on your hosting.

It can occur in particular after migrating a site, because of an old path saved in the configuration, a poorly configured extension, or a custom script.

Before you begin

Keep a copy of the file before modifying it. You must also have the complete error message in order to identify the denied path and the PHP file causing the problem.

Understanding the error message

The message may look like this example:

Warning: include(): open_basedir restriction in effect.
File(/home/old-host/public_html/config.php)
is not within the allowed path(s):
(/var/www/example.com/htdocs/:/tmp/)
in /var/www/example.com/htdocs/index.php on line 24

It contains several useful pieces of information:

  • /home/old-host/public_html/config.php is the file the script is trying to access;
  • /var/www/example.com/htdocs/ corresponds to the space where your site's files can be used;
  • /var/www/example.com/htdocs/index.php is the script that tried to open the file;
  • line 24 indicates the line concerned in this script.

In this example, the site is still using a path from an old hosting account. PHP therefore blocks access to the file.

Find the error in the PHP logs

If your site displays only a blank page or a 500 error, check the hosting logs:

  1. Open the Apache / PHP Logs tool.
  2. Reproduce the action that causes the problem on your site.
  3. Refresh the logs and look for the line containing open_basedir restriction in effect.
  4. Note the denied path and the PHP file indicated at the end of the message.

The most recent lines are usually found at the end of the log.

Fix the path used by the site

1. Check the actual location of the file

On LWS Panel, a site's public files are usually placed in a directory like this:

/var/www/your-domain.fr/htdocs/

Replace your-domain.fr with the domain name concerned.

Then check, from the file manager or via FTP, that the file you are looking for is indeed in this directory or one of its subfolders.

2. Find the old path

The incorrect path may be stored:

  • in a configuration file;
  • in a custom PHP script;
  • in the settings of an extension or a theme;
  • in the configuration of a cache, import, backup, or temporary files folder;
  • in data kept after a migration.

First look for the characteristic part of the old path, for example:

/home/old-host/

Do not randomly modify internal WordPress, PrestaShop, or other application files. Start by checking the configuration of the extension or module indicated in the error message.

3. Replace the incorrect path

Replace the old path with the real file path on your LWS hosting.

For example:

Old path :
/home/old-host/public_html/cache/

New path :
/var/www/your-domain.fr/htdocs/cache/

In a custom PHP script, it is often better to build the path from the script's folder rather than storing the full server path.

For example:

require __DIR__ . '/config.php';

This writing allows the script to look for config.php in its own folder.

The open_basedir directive cannot be modified or disabled from a .user.ini file on LWS Panel.

This protection must not be bypassed. You must correct the path used by the site, the script, or the extension.

4. Clear the application's cache

After correcting the path, clear the cache from your CMS or application interface.

An old path may remain stored in a cache file, even after the configuration has been changed.

Check that everything works

Reproduce exactly the action that caused the error: open the relevant page, submit the form, or restart the interrupted operation.

Then consult the PHP logs again. No new line containing open_basedir restriction in effect should appear.

The fix is complete when the relevant page or feature works again and no new open_basedir error appears in the PHP logs.

Common issues

I only see a 500 error or a blank page

The full message is probably stored in the PHP logs. Open the Apache / PHP Logs tool from LWS Panel, then reproduce the error before refreshing the log.

The path shown corresponds to my old host

An absolute path was not updated during migration. Search for this path in the configuration files, extension settings, and custom scripts.

Replace it with the current path of your site on LWS Panel.

I can't find where the path is stored

Look at the PHP file name shown at the end of the error message. It often helps identify the application, theme, extension, or script concerned.

For an extension, first check its cache, import, backup, or temporary file settings.

The file is in the htdocs folder, but the error continues

Check that the path used by the script exactly matches the file's actual location.

A symbolic link may also seem to point to a site file while directing PHP to a location outside the authorized space. In that case, replace the link with direct access to a file located in the site's folder.

The error returns after the modification

Clear your application's cache, then reproduce the problem. Also check that the path is not stored in multiple places.

help.lws.net/a/765
Was this article helpful?

Yes

No

Read 19 661 times

Thank you! Feel free to ask questions about our documentation if you would like more information, and help us improve it.

Similar articles

A question about this article?

Ask the LWS team and the community. Answers are published after moderation.

Ask the LWS team and its community a question

RGPD : Responsable LWS-Ligne Web Services. Finalité : modération et publication publique de votre question, notification éventuelle d'une réponse. Base légale : consentement (art. 6.1.a RGPD). Conservation des emails : 90 jours après notification, 12 mois maximum sans réponse. Vous pouvez exercer vos droits via notre nos CGV - section RGPD.