【问题标题】:Allow index a folder, but don't serve files允许索引文件夹,但不提供文件
【发布时间】:2017-06-02 22:13:02
【问题描述】:

我想允许 Nginx 自动索引文件夹,但不提供文件。 在我的应用程序中,文件存储在受保护的文件文件夹中,用户无法访问该文件夹。当用户调用一个文件(例如:my-website.com/files/my-great-files.pdf)时,实际上,他被重定向到一个 PHP 脚本,该脚本验证用户是否有权调用该文件。我知道该怎么做,没关系。

但实际上,我想使用一个名为 jBrowse 的 JS 插件,这个程序需要访问很多文件,并且需要访问文件夹的索引才能在其中包含文件列表。

我不知道该怎么做...我们可以在 PHP 中返回文件索引吗?

或者其他想法,允许 Nginx 返回包含空文件的文件夹的索引。当用户或插件想要访问该文件时,他会重定向到控制权限的 PHP 脚本。

我介意这个:

location /files {
  autoindexon;
}


location ~* \.(doc|pdf)$ {
  deny all;
}

没关系,用户可以在文件夹中导航,查看文件,但是如果他点击,就会出现 403 错误。但是我不能通过重定向到 php 来替换全部拒绝...

这是我的 default.conf 文件:

server {
server_name project.dev;
root /home/docker/web;

location / {
# try to serve file directly, fallback to app.php
 #try_files $uri /app.php$is_args$args;
try_files $uri /app_dev.php$is_args$args;
}

 location /protected_files {
internal;
 alias /home/docker/protected-files;
}

 location /files {
autoindex on;
}

 location ~* \.(doc|pdf)$ {
try_files $uri /app_dev.php$is_args$args;
}

# DEV
 # This rule should only be placed on your development environment
 # In production, don't include this and don't deploy app_dev.php or config.php
location ~ ^/(app_dev|config)\.php(/|$) {
fastcgi_pass engine:9000;
fastcgi_split_path_info ^(.+\.php)(/.*)$;
include fastcgi_params;
# When you are using symlinks to link the document root to the
 # current version of your application, you should pass the real
 # application path instead of the path to the symlink to PHP
 # FPM.
 # Otherwise, PHP's OPcache may not properly detect changes to
 # your PHP files (see https://github.com/zendtech/ZendOptimizerPlus/issues/126
 # for more information).
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
fastcgi_param DOCUMENT_ROOT $realpath_root;
}
# PROD
location ~ ^/app\.php(/|$) {
fastcgi_pass engine:9000;
fastcgi_split_path_info ^(.+\.php)(/.*)$;
include fastcgi_params;
# When you are using symlinks to link the document root to the
 # current version of your application, you should pass the real
 # application path instead of the path to the symlink to PHP
 # FPM.
 # Otherwise, PHP's OPcache may not properly detect changes to
 # your PHP files (see https://github.com/zendtech/ZendOptimizerPlus/issues/126
 # for more information).
fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
fastcgi_param DOCUMENT_ROOT $realpath_root;
# Prevents URIs that include the front controller. This will 404:
 # http://domain.tld/app.php/some-path
 # Remove the internal directive to allow URIs like this
 #internal;
}

 error_log /var/log/nginx/project_error.log;
access_log /var/log/nginx/project_access.log;
}

【问题讨论】:

    标签: nginx nginx-location


    【解决方案1】:

    您可以将deny all 替换为rewrite 指令,以执行到您的php 处理程序的内部重定向。

    location /files {
        autoindex on;
    }
    
    location ~* ^/files.*\.(doc|pdf)$ {
        rewrite ^ /app_dev.php last;
    }
    

    详情请见this document。

    编辑:您可能希望使您的正则表达式更加具体,以便只有以 /files 开头并以 .doc 或 .pdf 结尾的 URI 匹配。更改正则表达式(如上)或将其嵌套在 location /files 块中,如下所示:

    location /files {
        autoindex on;
    
        location ~* \.(doc|pdf)$ {
            rewrite ^ /app_dev.php last;
        }
    }
    

    【讨论】:

    • 谢谢你,它工作得很好。当我的脚本只返回响应或生成文件时,就可以了。但是当我使用 X-Accel 时,它不起作用。我搜索为什么,但如果你有一个想法。在我的脚本中,我控制用户权限,然后在 /protected_files 上使用 X-Accel 重定向。但是有了这个,它就行不通了。
    • @Sheppard 我已经更新了我的答案,提出了两个建议供您尝试。
    • 再次感谢,我已经尝试通过修改正则表达式(它的工作),但我更喜欢你的位置重叠。对不起,我真的不知道nginx。再次感谢你:)
    猜你喜欢
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2018-09-19
    • 2020-06-10
    • 2017-08-10
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多