我有一个nginx + Apacheconfiguration运行。 我对nginx非常新,我有相当长的时间来学习它。
首先我想做一个基本的重写。 根据我的理解,当nginx被用作反向代理时,来自apache的.htaccess仍然可以工作。 可悲的是 – 我的理解不完全正确 – 有些部分是有效的,有些则不是。
所以我试图用.htaccess做一个基本的重写
RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule ^/?index.* /fp/ [P]
我发现在.htaccess中使用[P]标志而不是正常的重写 – 会导致无法find/index.html的错误(在整个站点上没有任何index.html如此清晰它不能被发现)。
我也尝试过使用[L]标志,而不是像我期望的那样默默转发,而是做了一个redirect,所以用户可以在地址栏中看到/ fp /而不是我正在寻找的结果。
所以 – 我把redirect移到了nginxconfiguration。 这似乎工作正常。
我做的nginxredirect是非常基本的使用if语句
if ($uri = '/'){ rewrite / /fp/ break; }
这个redirect只会redirect/不在/index.php或其他任何文件上。
接下来我有一个名为/login.php的文件。 我想转发用户到https://如果通过http://访问
所以我试图用$_SERVER['REQUEST_SCHEME'];做一个apachescheme检查$_SERVER['REQUEST_SCHEME']; 问题是 – 这是返回http是否其https://或http://
login.php在/
所以对于初学者来说,我怎么才能让httpredirect到https只在login.php页面上。
我也应该注意到我试图做一个从httpredirect到https使用.htaccess,但作为服务器返回http和从来没有https导致无限循环。
除此之外,为什么apache的.htaccess [P]标志导致searchindex.html,并且为什么silectredirect突然公开?
如果我需要显示我的configuration – 请告诉我哪些:)
更新显示configuration
nginx.conf
server { proxy_pass_request_headers on; index index.php; listen 192.227.210.138:80; server_name adsactlyhits.com www.adsactlyhits.com; error_log /var/log/apache2/domains/adsactlyhits.com.error.log error; location / { if ($uri = '/'){ rewrite / /fp/ break; } proxy_pass http://192.227.210.138:8080; location ~* ^.+\.(jpeg|jpg|png|gif|bmp|ico|svg|tif|tiff|css|js|ttf|otf|webp|woff|txt|csv|rtf|doc|docx|xls|xlsx|ppt|pptx|odf|odp|ods|odt|pdf|psd|ai|eot|eps|ps|zip|tar|tgz|gz|rar|bz2|7z|aac|m4a|mp3|mp4|ogg|wav|wma|3gp|avi|flv|m4v|mkv|mov|mpeg|mpg|wmv|exe|iso|dmg|swf)$ { root /home/adsactly/web/adsactlyhits.com/public_html; access_log /var/log/apache2/domains/adsactlyhits.com.log combined; access_log /var/log/apache2/domains/adsactlyhits.com.bytes bytes; expires max; try_files $uri @fallback; } } location /error/ { alias /home/adsactly/web/adsactlyhits.com/document_errors/; } location @fallback { proxy_pass http://192.227.210.138:8080; } location ~ /\.svn/ {return 404;} location ~ /\.git/ {return 404;} location ~ /\.hg/ {return 404;} location ~ /\.bzr/ {return 404;} include /home/adsactly/conf/web/nginx.adsactlyhits.com.conf*; }
snginx.conf
server { listen 192.227.210.138:443; server_name adsactlyhits.com www.adsactlyhits.com; ssl on; ssl_certificate /home/adsactly/conf/web/ssl.adsactlyhits.com.pem; ssl_certificate_key /home/adsactly/conf/web/ssl.adsactlyhits.com.key; error_log /var/log/apache2/domains/adsactlyhits.com.error.log error; location / { if ($uri = '/'){ rewrite / /fp/ break; } proxy_pass http://192.227.210.138:8080; proxy_cache cache; proxy_cache_valid 15m; proxy_cache_valid 404 1m; proxy_no_cache $no_cache; proxy_cache_bypass $no_cache; proxy_cache_bypass $cookie_session $http_x_update; location ~* ^.+\.(jpeg|jpg|png|gif|bmp|ico|svg|tif|tiff|css|js|ttf|otf|webp|woff|txt|csv|rtf|doc|docx|xls|xlsx|ppt|pptx|odf|odp|ods|odt|pdf|psd|ai|eot|eps|ps|zip|tar|tgz|gz|rar|bz2|7z|aac|m4a|mp3|mp4|ogg|wav|wma|3gp|avi|flv|m4v|mkv|mov|mpeg|mpg|wmv|exe|iso|dmg|swf)$ { proxy_cache off; root /home/adsactly/web/adsactlyhits.com/public_html; access_log /var/log/apache2/domains/adsactlyhits.com.log combined; access_log /var/log/apache2/domains/adsactlyhits.com.bytes bytes; expires max; try_files $uri @fallback; } } location /error/ { alias /home/adsactly/web/adsactlyhits.com/document_errors/; } location @fallback { proxy_pass http://192.227.210.138:8080; } location ~ /\.ht {return 404;} location ~ /\.svn/ {return 404;} location ~ /\.git/ {return 404;} location ~ /\.hg/ {return 404;} location ~ /\.bzr/ {return 404;} include /home/adsactly/conf/web/nginx.adsactlyhits.com.conf*; }
http://theurl.com/test.php
<?php echo $_SERVER['REQUEST_SCHEME']; ?>
返回:http
https://theurl.com/test.php
<?php echo $_SERVER['REQUEST_SCHEME']; ?>
返回:http
所以对于初学者来说,我怎么才能让httpredirect到https只在login.php页面上
关键是http和https的不同服务器块。 如果您从单个服务器块提供服务,则您的控制权限会更有限。 像这样的东西应该工作。
server { server_name example.com; listen 80; location = login.php { return 302 https://example.com/login.php; } } server { server_name example.com; listen 443 ssl; # define any locations required }
更大的图片,你应该通过https服务你的整个网站,以避免这些问题,除非有一个很好的理由,你必须使用HTTP。 您的应用程序可能必须注意,通过http和https分段的网站才能支持此设置。
而且,Nginx和Apache通常是不必要的。 Nginx可以完成Apache可以做的大部分事情,并且使用这两者都会增加复杂性。
任何时候你发现自己需要在Nginx中使用“if”,你应该考虑Nginx的“if is evil”这篇文章 。 我使用if,但只是为控制caching指令设置variables,而不是用于任何关键或stream量相关的。 尽可能避免使用“if”。
更新
本文向您介绍如何将标题(如协议)传递到下一层,以便知道原始协议。 你最好是完全摆脱Apache,让Nginx使用php-fpm调用PHP。
location / { proxy_set_header HOST $host; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_pass http://example.com/new/prefix; }
删除,如果redirect
而不是这个
location / { if ($uri = '/'){ rewrite / /fp/ break; } // etc }
你可以尝试这样的事情。 等号运算符是完全匹配的运算符。 这将会给予更好的性能(稍微)和更可靠的操作。
location = / { rewrite / /fp/ break; } location / { // etc }
我没有使用自己的重写,所以我不知道这是做你想做的任何事情的最好方法。