【发布时间】:2020-05-18 19:10:15
【问题描述】:
基于该架构:
├── application
├── assets
├── bloxby_enterprise_1_4_0.zip
├── build
├── ci_3.1.9
├── config.ini
├── elements
├── _htaccess
├── images
├── img
├── index.php
├── install
├── license.txt
├── Makefile
├── node_modules
├── package.ini
├── package.json
├── package-lock.json
├── README-.md
├── README.md
├── tmp
├── vendor
└── webpack.config.js
我正在尝试使用 nginx 公开我的网站。我的 index.php 重定向到 /install 位于另一个 index.php 的地方,假设它会启动我的安装。
我成功暴露了我的网站并点击了第一个 index.php。进行了重定向,但我陷入了无限循环。有什么线索吗?这是我的 nginx 配置文件。
server {
index index.php;
listen 80;
server_name XXX;
return 301 https://XXX$request_uri;
}
server {
listen 443;
ssl on;
server_name XXX;
root /opt/participate;
index index.php /install/.index.php
error_log /var/log/nginx/XXX.log;
access_log /var/log/nginx/XXX.log;
ssl_certificate /etc/letsencrypt/live/XXX/fullchain.pem; # managed by Certbot
ssl_certificate_key /etc/letsencrypt/live/XXX/privkey.pem; # managed by Certbot
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
location / {
try_files $uri /index.php$is_args$args;
}
location ~ ^/index\.php(/|$) {
fastcgi_pass localhost:9000;
fastcgi_split_path_info ^(.+\.php)(/.*)$;
include fastcgi_params;
fastcgi_param SCRIPT_FILENAME $request_filename;
fastcgi_param DOCUMENT_ROOT $realpath_root;
internal;
}
# return 404 for all other php files not matching the front controller
# this prevents access to other php files you don't want to be accessible.
#location ~ \.php$ {
# return 404;
#}
}
【问题讨论】:
-
您应该考虑将公共文件移动到专用文件夹中。经常使用“公共”。并让网络服务器将此文件夹用作文档根目录。因为通过您的设置,每个文件都会被公开。特别是 config.ini 可能是一个安全问题。
-
请发布您的主要 index.php 部分,您将重定向到安装 index.php
-
你的配置只执行一个PHP文件,即
/index.php。任何其他以.php结尾的URI(例如/install/index.php)都不会匹配您在location语句中使用的正则表达式。因此,如果index.php尝试重定向到另一个.php文件,它将被try_files语句重定向回自身。