You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AlmaLinux+Plesk环境下GLPI安全目录配置问题求助

解决GLPI 10.0.17在Plesk+AlmaLinux 9.5+NGINX下的安全目录检查报错

一、修正目录结构与配置文件定义

1. 目录权限与归属校准

  • 将/var/www/vhosts/yourdomain.com/internal/及其子目录的所有者设为Plesk对应站点的web用户(通常是nginx或站点专属系统用户),目录权限设为750,文件权限设为640。
  • 将/var/www/vhosts/yourdomain.com/subdomain/(GLPI主体目录)的所有者设为同一用户,权限设为755。

2. 修正inc/downstream.php内容

确保该文件准确指向配置目录并引入自定义配置:

<?php
define('GLPI_CONFIG_DIR', '/var/www/vhosts/yourdomain.com/internal/config/');

if (file_exists(GLPI_CONFIG_DIR . '/local_define.php')) {
   require_once GLPI_CONFIG_DIR . '/local_define.php';
}

3. 完善config/local_define.php内容

补充所有非公共目录的定义,确保路径与实际目录一致:

<?php
define('GLPI_VAR_DIR', '/var/www/vhosts/yourdomain.com/internal/files/');
define('GLPI_LOG_DIR', GLPI_VAR_DIR . 'logs/');
define('GLPI_MARKETPLACE_DIR', '/var/www/vhosts/yourdomain.com/internal/marketplace/');

// 自动创建日志目录(仅首次执行生效)
if (!is_dir(GLPI_LOG_DIR)) {
   mkdir(GLPI_LOG_DIR, 0750, true);
}

二、配置NGINX站点规则(核心修复)

在Plesk后台进入子域名设置 > Apache & NGINX Settings > Additional NGINX directives,替换原有指令为以下内容:

# 关键:将网站根目录指向GLPI的public子目录(GLPI 10.x标准公共入口)
root /var/www/vhosts/yourdomain.com/subdomain/public;

# 禁止访问所有隐藏文件
location ~ /\. {
    deny all;
}

# 双重防护:禁止直接访问GLPI非公共目录
location ~ ^/(inc|config|install|vendor|locales) {
    deny all;
}

# 适配GLPI的URL重写规则
location / {
    try_files $uri $uri/ /index.php$is_args$args;
}

# PHP-FPM配置(根据Plesk实际套接字路径调整,若不确定可查看Plesk PHP设置)
location ~ \.php$ {
    include snippets/fastcgi-php.conf;
    fastcgi_pass unix:/var/www/vhosts/system/yourdomain.com/php-fpm.sock;
    fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    include fastcgi_params;
}

注:如果之前将NGINX根目录指向/var/www/vhosts/yourdomain.com/subdomain/,必须替换为public子目录——这是GLPI安全检查通过的核心前提,因为非公共文件均位于public之外,web server无法直接访问。

三、验证open_basedir配置

在Plesk子域名设置 > PHP Settings > open_basedir中确保包含以下目录:

/var/www/vhosts/yourdomain.com/subdomain/:/var/www/vhosts/yourdomain.com/internal/:/tmp/:/var/tmp/

四、生效配置并验证

  1. 重启NGINX与PHP-FPM服务:
systemctl restart nginx
systemctl restart php-fpm
  1. 访问https://subdomain.yourdomain.com,检查安全错误是否消失。
  2. 若问题依旧,查看GLPI日志文件/var/www/vhosts/yourdomain.com/internal/files/logs/php-errors.log,排查路径定义或权限问题。

内容的提问来源于stack exchange,提问作者mainmind83

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 23:12:47