1

我试图限制对我的网站的访问,只允许特定的 IP,我遇到了以下问题:当我访问 www.example.com 时,拒绝工作完美,但是当我尝试访问 www.example.com/index 时。 php 它返回“拒绝访问”页面,并且 php 文件直接在浏览器中下载,无需处理。我确实想拒绝访问网站上除我之外的所有 IP 的所有文件。我该怎么做?

这是我的配置:

server {
listen 80;
server_name example.com; 
root /var/www/example;

location / {
    index index.html index.php; ## Allow a static html file to be shown first
    try_files $uri $uri/ @handler; ## If missing pass the URI to front handler
    expires 30d; ## Assume all files are cachable
 allow my.public.ip;
 deny all;
}

location @handler { ## Common front handler
    rewrite / /index.php;
}
location ~ .php/ { ## Forward paths like /js/index.php/x.js to relevant handler
    rewrite ^(.*.php)/ $1 last;
}

location ~ .php$ { ## Execute PHP scripts
    if (!-e $request_filename) { rewrite / /index.php last; } ## Catch 404s that try_files miss

    expires        off; ## Do not cache dynamic content
    fastcgi_pass   127.0.0.1:9001;
    fastcgi_param  HTTPS $fastcgi_https;
    fastcgi_param  SCRIPT_FILENAME  $document_root$fastcgi_script_name;
    include        fastcgi_params; ## See /etc/nginx/fastcgi_params
    }
}
4

2 回答 2

0

那是因为您的拒绝/允许规则仅适用于一个位置。

删除它并尝试:

server {
    listen 80;
    server_name example.com; 
    root /var/www/example;
    if ($remote_addr != "YOUR.PUBLIC.IP") {return 403;}
    ...
}

由于测试在任何特定位置块之外,它将适用于所有情况。

另请注意,这IF并不是邪恶的,因为它只是“返回”。

于 2013-10-18T02:28:49.363 回答
0

好的,所以我找到了解决方案。Nginx 处理最精确的正则表达式,在这种情况下是 php 文件的正则表达式。要使配置正常工作,必须在 / location 规则中定义除 @handler 之外的所有其他位置(您不能置于任何规则之下 - 只能作为 root 用户)

server {
listen 80;
server_name example.com; 
root /var/www/example;

    location / {
    index index.html index.php; ## Allow a static html file to be shown first
    try_files $uri $uri/ @handler; ## If missing pass the URI to front handler
    expires 30d; ## Assume all files are cachable
    allow my.public.ip;
    deny all;

    location ~ .php/ { ## Forward paths like /js/index.php/x.js to relevant handler
        rewrite ^(.*.php)/ $1 last;
    }

    location ~ .php$ { ## Execute PHP scripts
        if (!-e $request_filename) { rewrite / /index.php last; } ## Catch 404s that try_files miss

        expires        off; ## Do not cache dynamic content
        fastcgi_pass   127.0.0.1:9001;
        fastcgi_param  HTTPS $fastcgi_https;
        fastcgi_param  SCRIPT_FILENAME  $document_root$fastcgi_script_name;
        include        fastcgi_params; ## See /etc/nginx/fastcgi_params
        }
}

    location @handler { ## Common front handler
        rewrite / /index.php;
    }

}
于 2013-10-19T19:42:19.407 回答