【问题标题】:nginx and git-http-backend 403 on pushnginx 和 git-http-backend 403 推送
【发布时间】:2020-09-03 15:54:05
【问题描述】:

我正在尝试设置一个 git 服务器,前端使用 stagit,后端使用 git-http-backend,并在所有内容之间使用 nginx。我在this 答案中找到了一个可以在我的服务器上运行的配置(通过工作,我的意思是 nginx 将通过网络浏览器为任何连接提供 html,但如果我使用git clone https://git.website.com/test.git,我可以克隆一个存储库。

我遇到的问题是,当我推送这个来源为https://git.website.com/test.git 的存储库(无论是来自服务器本身还是来自我的本地计算机)时,我收到一个 403 错误,我不确定为什么。有什么想法吗?

server {
    listen 80;
    listen [::]:80;

    listen 443 ssl;
    listen [::]:443 ssl;

    ssl_certificate /etc/ssl/ssl-bundle.crt;
    ssl_certificate_key /etc/ssl/private/ssl-private.key;

    root /srv/git;

    index index.html index.htm index.nginx-debian.html;

    access_log /var/log/nginx/git.access.log;
    error_log /var/log/nginx/git.error.log;
    gzip off;

    location / {
        try_files $uri $uri/ =404;
    }

    # static repo files for cloning over https
    location ~ ^.*/objects/([0-9a-f]+/[0-9a-f]+|pack/pack-[0-9a-f]+.(pack|idx))$ {
        root /srv/git;
    }

    # requests that need to go to git-http-backend
    location ~ ^.*/(HEAD|info/refs|objects/info/.*|git-(upload|receive)-pack)$ {
        root /srv/git;

        fastcgi_pass  unix:/var/run/fcgiwrap.socket;
        fastcgi_param SCRIPT_FILENAME   /usr/lib/git-core/git-http-backend;
        fastcgi_param PATH_INFO         $uri;
        fastcgi_param GIT_PROJECT_ROOT  $document_root;
        fastcgi_param GIT_HTTP_EXPORT_ALL "";
        fastcgi_param REMOTE_USER $remote_user;
        include fastcgi_params;
    }   
}

大约两个小时前我才开始尝试使用git-http-backend 和多个配置。让 http 正常服务网页似乎非常困难,但 也 允许 git 克隆/推送。使用找到的配置 here 导致空的 200 OK 响应...

【问题讨论】:

    标签: git nginx push fastcgi http-status-code-403


    【解决方案1】:

    经过多次试验和错误,我从this 答案中获取了配置,并对其进行了修改以提供以下位置规则:

    location / {
        if ($arg_service = git-receive-pack) {
            rewrite (/.*) /git_write/$1 last;
        }
    
        if ($uri ~ ^/.*/git-receive-pack$) {
            rewrite (/.*) /git_write/$1 last;
        }
    
        if ($arg_service = git-upload-pack) {
            rewrite (/.*) /git_read/$1 last;
        }
    
        if ($uri ~ ^/.*/git-upload-pack$) {
            rewrite (/.*) /git_read/$1 last;
        }
    }
    
    # pass PHP scripts to FastCGI server
    location ~ \.php$ {
        include snippets/fastcgi-php.conf;
        fastcgi_pass unix:/run/php/php7.3-fpm.sock;
    }
    
    location ~ /git_read/(.*) {
        include git-http-backend.conf;
    }
    
    # require auth to upload
    location ~ /git_write/(.*) {
        auth_basic "Pushing to Git repositories is restricted";
        auth_basic_user_file /etc/nginx/htpasswd;
        include git-http-backend.conf;
    }
    

    /etc/nginx/git-http-backend.conf 写着:

    fastcgi_pass unix:/var/run/fcgiwrap.socket;
    include fastcgi_params;
    fastcgi_param SCRIPT_FILENAME /usr/lib/git-core/git-http-backend;
    fastcgi_param GIT_HTTP_EXPORT_ALL "";
    fastcgi_param GIT_PROJECT_ROOT /srv/git;
    fastcgi_param PATH_INFO $1;
    fastcgi_param REMOTE_USER $remote_user;
    

    问题解决了。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2018-09-30
      • 2023-03-30
      • 1970-01-01
      • 2020-09-15
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2017-04-16
      相关资源
      最近更新 更多