【问题标题】:Force Non-SSL (http) on particular page and SSL on all other pages by .htaccess通过 .htaccess 在特定页面上强制非 SSL (http) 和所有其他页面上的 SSL
【发布时间】:2014-04-11 13:15:22
【问题描述】:

我正在使用 Zend-Framework,下面是我的 htaccess 的代码。

rewriteEngine On

RewriteCond %{HTTPS} =off
RewriteRule ^(.*)$ https://www.mysite.co/$1 [R=301,L] 
RewriteCond %{http_host} ^mysite.co [NC]
RewriteRule ^(.*)$ https://www.mysite.co/$1 [R=301,L] 

RewriteCond %{REQUEST_FILENAME} -s [OR]
RewriteCond %{REQUEST_FILENAME} -l [OR]
RewriteCond %{REQUEST_FILENAME} -d
RewriteRule ^.*$ - [NC,L]
RewriteRule ^.*$ index.php [NC,L]

现在我想在 mysite.co/news/* 上强制 http 和在所有其他页面上强制 https。那么如何应用规则呢?

【问题讨论】:

  • 只是指出,当客户端能够从https:// 重定向到http:// 时,它已经发出了 HTTPS 请求,因此握手(“ SSL/TLS 的昂贵”部分)已经发生。不确定您是否会在此之后获得您想要实现的优化,如果那是您想要做的。

标签: http zend-framework ssl https


【解决方案1】:

您可以定义您的控制器和操作并将此代码置于该条件下,为此您可以使用 zend 框架的引导程序。

喜欢:

if($_SERVER['SERVER_PORT'] == '443') {
    header('Location: http://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']);
    exit();
}

或者你可以使用这个引导方法

protected function _initForceSSL() {
    if($_SERVER['SERVER_PORT'] == '443') {
        header('Location: http://' . $_SERVER['HTTP_HOST'] . $_SERVER['REQUEST_URI']);
        exit();
    }
}

【讨论】:

    【解决方案2】:

    存在isSecure() 函数,可以让您知道它是 https 请求 (true) 还是 http (错误)。
    您可以尝试通过这样的插件来重定向您的查询:

    class Application_Plugin_SSL extends Zend_Controller_Plugin_Abstract
    {
    
        public function dispatchLoopStartup(Zend_Controller_Request_Abstract $request){
    
          if (!$request->isSecure()){ // -> not https
    
                $request->setModuleName('yourmodule')
                        ->setControllerName('yourcontrolle')
                        ->setActionName('youraction')
                        ->setDispatched(true) ;
          }
        }
    }
    

    【讨论】:

      猜你喜欢
      • 2013-01-22
      • 2012-05-19
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2015-07-14
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多