Managing Rules

Managing Rules

Use the Content Restrictions screen to add, edit, disable, or delete URL password rules. Search the table by label, category path, or URL.

Add or edit a rule

  1. Open Content Restrictions.
  2. Select Add URL Restriction, or select Edit on an existing row.
  3. Complete the fields below.
  4. Select Add Rule for a new restriction, or Save Rule for an existing one.

To remove a rule, select Delete and confirm. Use Enabled to turn a rule off without deleting it.

URL Pattern

Each rule protects a storefront path.

  • Enter the path visitors use, for example /partner-login/ or /brands/nike/sale/.
  • Use * to match one URL segment, for example /brands/*/sale/.
  • The URL Pattern controls where the password prompt appears. A category link is optional.

Each store can have only one rule per URL path. The same password can be used on many rules. Each password can be up to 255 characters.

Label and category helper

  • Label appears in the admin list. If you leave it blank, the app uses the URL as the label.
  • Fill from category (optional) copies that category’s URL and name into the form. Leave it empty for a product page, CMS page, or custom path.

Protecting a category URL does not lock product pages that use a different URL. Add a rule for each product or page path you need to protect, or use a matching wildcard.

Parent path password inheritance

A parent URL rule can also protect child paths. For example, /partners/ can protect /partners/school-a/.

Inherit Parent Path Password is on by default. Leave it on when a child path should use the nearest matching parent URL rule password.

Turn Inherit Parent Path Password off on a child rule when that child needs its own password.

Wildcard parent patterns that include * do not pass their password down to child paths. Add an explicit rule for those child URLs if they must be protected.

Channels, prompts, and unlock time

  • Apply a rule to selected channels, or select Apply to all channels.
  • New rules start on the default storefront channel.
  • Set a Prompt Message for the storefront form. If you leave it blank, the rule uses the Default Prompt Message from General Settings.
  • Set Unlock Minutes for how long a successful unlock lasts in that browser. The minimum is 1 minute.

Password visibility

In General Settings, Reveal passwords by default controls whether passwords start visible in rule forms.

Use Show and Hide in the add or edit form to change visibility. Passwords saved before viewing was supported must be replaced once before they can be viewed.

Export CSV

  1. Open Content Restrictions.
  2. Select Download Restrictions CSV.

Exports include rule settings. They do not include passwords.

Import CSV

  1. Select Upload CSV.
  2. Optionally select Download All Categories to get every store category with its ID, name, full category path, and URL path. Keep the rows you want to restrict and add a password column for new restrictions.
  3. Choose a CSV file. Common headings such as category, name, pass, and url are recognized.
  4. Choose Category matching sensitivity if a row needs help matching a BigCommerce category. Balanced is recommended.
  5. Select Prepare and preview. Confirm any suggested category matches.
  6. Choose Merge with existing restrictions or Delete existing restrictions before upload.
  7. Import the ready rows.

Import notes:

  • Rows are matched by URL path first. Category ID is optional.
  • Include a password column only when you set a new password or replace an existing one.
  • New rows require a password.
  • Delete existing restrictions before upload removes all current rules and replaces them with the CSV.

Related articles


Did you find this article useful?