Permission denied in a Node.js or Python app on cPanel: ownership, modes and folders

EACCES: permission denied in Node.js, PermissionError: [Errno 13] in Python. The application tried to do something its user cannot. The short answer: on a shared account the application runs as the same user as the account, so the error is almost never “no permission over your own files”, and nearly always one of two things: it is trying to write or install outside the account, or the folder has the wrong mode or owner after a transfer.

What the message means

What you see Usual cause What to do
Error writing a data or upload file The folder does not exist, is not yours, or the path points outside the account (for example /var or a fixed /tmp/... in the code). Use a folder inside the account, created by you, with a path relative to the application.
sqlite3.OperationalError: unable to open database file or “attempt to write a readonly database” SQLite needs to write to the file and to the folder it sits in (it creates temporary files beside it). Put the database in a folder the account can write to. For more than one user at a time, prefer MariaDB: connecting to your database from Python and Node.js.
EACCES on npm install A global install (-g) or sudo. Install inside the application’s environment, without -g. See npm install errors.
EACCES when listening on a port The application asks for a port below 1024 (80, 443). Only root can. Do not open ports: here the application is served through the domain. Use process.env.PORT.
EPERM: operation not permitted Changing the owner or mode of a file that is not yours (chown, chmod), or deleting something protected. You can only change what is yours. Files uploaded by another user or restored from a backup may have the wrong owner: open a ticket.
403 Forbidden in the browser, not in the application Not the application: the web server is refusing a file or folder. Error 403: permissions, .htaccess and blocked IPs.

The modes that are usually right

1 Folders at 755 and files at 644 are the norm for code. In Terminal: find . -type d -exec chmod 755 {} +
find . -type f -exec chmod 644 {} +
Run it inside the application folder, and never at the account root. Do not touch the node_modules folder or the virtual environment: the tool created them.
2 The startup file (app.js, passenger_wsgi.py) must be readable, not executable. If you uploaded it over FTP, check the mode in the client: FileZilla and permissions.
3 Folders the application writes to (uploads, temporary files, the SQLite database) must belong to the account user and be writable by the owner, which 755 already gives. You do not need more.
4 Restart the application and repeat the action that failed.
Never fix it with chmod 777. It gives write access to everybody, it is the opening attackers like best, and it is almost never what was missing. If 777 “fixed” it, the real problem was the owner or the path: find out which, instead of leaving the door open.
See the owner and mode of a file with ls -l file and of a folder with ls -ld folder. The first column is the mode; the third is the owner. If the owner is not the account user, that is where to look. For the terminal: the cPanel Terminal.

The owner or mode look wrong and you cannot change them? Send us the domain and the file path.

Open a support ticket

SEE ALSO

npm install fails with EACCES, ERESOLVE or out of memory

Error 403 Forbidden: permissions, .htaccess and blocked IPs

Connecting to your database from Python and Node.js

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.59/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?