You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS上Spring Boot+Nginx文件上传异常:1KB正常250KB报403禁止

问题

在AWS上运行的Spring Boot应用,用于向S3上传文件。1KB的TXT文件上传正常,但250KB的TXT文件上传时返回403 Forbidden错误,且Nginx的访问/错误日志无任何记录,请求也未到达Tomcat。即使移除了保存到磁盘/S3的逻辑,仍会立即触发403 Forbidden错误。

控制器代码

@GetMapping("/inputuploads") 
public String listInputUploads(Model model) {
    logger.info("Renedering upload page");
    return "inputuploads";
}

@PostMapping("/inputuploads")
public String saveFile(Model model, @RequestParam("file") MultipartFile file, RedirectAttributes ra) throws IOException {       
    logger.info("Saving file:"+file.getOriginalFilename());
    ra.addFlashAttribute("message","Uploaded file: "+ file.getOriginalFilename());      
    return "redirect:/inputuploads";
}

模板代码

<div th:if="${message}">
        <div th:text="${message}">                    
        </div>                              
</div>
           
<div >
    <form method="post" th:action="@{/inputuploads}" enctype="multipart/form-data" >
                                
        <div>                        
            <input type="file" name="file" accept=".xlsm" >                                          
        </div>
        
        <div>
            <button type="submit" >Upload</button>
        </div>
        
    </form>                
</div>

application.yml配置

spring:
  servlet:
    multipart:
      max-file-size: 100MB
      max-request-size: 100MB
      
server:
  port: 5000
  tomcat:
    max-swallow-size: -1 

.platform/nginx/nginx.conf配置

user                    nginx;
error_log               /var/log/nginx/error.log warn;
pid                     /var/run/nginx.pid;
worker_processes        auto;
worker_rlimit_nofile    32633;

events {
    worker_connections  1024;
}

http {
    include       /etc/nginx/mime.types;
    default_type  application/octet-stream;

    log_format  main  '$remote_addr - $remote_user [$time_local] "$request" '
                      '$status $body_bytes_sent "$http_referer" '
                      '"$http_user_agent" "$http_x_forwarded_for"';

    include       conf.d/*.conf;

    map $http_upgrade $connection_upgrade {
        default     "upgrade";
    }

    server {
        listen 80;
        return 301 https://$host$request_uri;
    }

    server {
        listen 443 ssl default_server;

        ssl_certificate certificates/localhost.crt;
        ssl_certificate_key certificates/localhost.key;
        

        access_log    /var/log/nginx/access.log main;
        
        client_header_timeout 1d;
        client_body_timeout   1d;
        client_max_body_size 100M;
        keepalive_timeout     1d;
        proxy_connect_timeout 1d;
        proxy_read_timeout 1d;
        proxy_send_timeout 1d;
        gzip                  off;
        gzip_comp_level       4;
        gzip_types text/plain text/css application/json application/javascript application/x-javascript text/xml application/xml application/xml+rss text/javascript;

        include conf.d/elasticbeanstalk/*.conf;
    }
}

.platform/nginx/conf.d/client_max_body_size.conf配置

client_max_body_size 100M;

.platform/nginx/conf.d/elasticbeanstalk/00_application.conf配置

location / {
    proxy_pass http://127.0.0.1:5000;

    proxy_http_version  1.1;

    proxy_set_header    Connection          $connection_upgrade;
    proxy_set_header    Upgrade             $http_upgrade;
    proxy_set_header    Host                $host;
    proxy_set_header    X-Real-IP           $remote_addr;
    proxy_set_header    X-Forwarded-For     $proxy_add_x_forwarded_for;
}

.ebextensions/00-set-timezone.config配置

commands:
  set_time_zone:
    command: ln -f -s /usr/share/zoneinfo/Asia/Kolkata /etc/localtime

解决方案

由于请求既没进入Nginx日志,也未到达Tomcat,问题大概率出在AWS前端防护组件或平台配置层面,按以下步骤排查:

1. 检查WAF(Web应用防火墙)规则

若Elastic Beanstalk环境关联了WAF Web ACL,登录AWS控制台进入WAF服务,查看是否有拦截请求体大小的规则,或恶意请求检测规则误触发了403。调整规则阈值,添加允许100MB请求体的白名单规则。

2. 验证ALB(应用负载均衡器)配置

  • 开启ALB访问日志,上传大文件后查看日志,确认请求是否到达ALB,以及返回403的具体原因(日志中会标记如waf_blocked等字段)。
  • 检查ALB是否有默认的请求大小限制,部分场景下ALB会在Nginx之前拦截超大请求。

3. 确认Nginx配置是否生效

登录EC2实例执行以下命令:

# 测试配置合法性
nginx -t
# 重载配置
nginx -s reload
# 确认client_max_body_size配置存在
cat /etc/nginx/conf.d/client_max_body_size.conf

若.platform目录配置未生效,改用.ebextensions添加Nginx配置:

files:
  "/etc/nginx/conf.d/00_client_max_body_size.conf":
    mode: "000644"
    owner: root
    group: root
    content: |
      client_max_body_size 100M;

4. 排查其他安全组件

  • 检查AWS Shield Advanced是否有防护规则拦截大请求。
  • 确认EC2实例的IAM角色权限无临时变更(小文件能正常上传,此概率较低)。

内容的提问来源于stack exchange,提问作者itsraja

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.21 11:15:01