You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Laravel应用HTTP正常运行,HTTPS访问报403错误求助

Laravel应用HTTPS访问403错误排查与解决

问题描述

HTTP协议下Laravel应用可正常运行,但HTTPS访问时页面空白,控制台报错:

Failed to load resource: the server responded with a status of 403 ()

已配置SSL证书,HTTP/HTTPS链接均可访问,但仅HTTP版本能正常加载数据。

环境信息

  • 操作系统:Ubuntu 22.04
  • 主机面板:aaPanel
  • Web服务器:Nginx

已配置内容

Laravel .env配置

APP_NAME='TradeWithShine Exchange'
APP_ENV=production
APP_KEY=base64:PqJTkxOD1loJIUnMtvkhmKLYTa/NFbsJtkQR0dxaQx8=
APP_DEBUG=false
APP_URL=https://coinspay.xyz
SANCTUM_STATEFUL_DOMAINS="coinspay.xyz"
LOG_CHANNEL=stack
TRADE_FREQUENCY=10

USER_ASSETS="false"
USER_ASSETS_HASH="1708829973402"

当前Nginx主配置(业务站点部分)

server {
    listen 80;
    root /www/wwwroot/coinspay.xyz/public;
    index index.php index.html index.htm;
    server_name coinspay.xyz;
    client_max_body_size 80M;

    location / {
        try_files $uri $uri/ /index.php$is_args$query_string;
    }

    location = /favicon.ico { access_log off; log_not_found off; }
    location = /robots.txt  { access_log off; log_not_found off; }

    error_page 404 /index.php;

    location ~ \.php$ {
        fastcgi_pass unix:/tmp/php-cgi-81.sock;
        fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
        include fastcgi_params;
    }

    location ~ /\.ht {
        deny all;
    }

    location /socket.io {
        proxy_pass https://localhost:6001;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;
    }
}

排查与解决步骤

1. 补充HTTPS站点Nginx配置

当前仅配置了80端口的HTTP站点,缺失443端口的HTTPS配置块。添加以下配置(替换证书路径为aaPanel生成的实际路径):

server {
    listen 443 ssl http2;
    listen [::]:443 ssl http2;
    root /www/wwwroot/coinspay.xyz/public;
    index index.php index.html index.htm;
    server_name coinspay.xyz;
    client_max_body_size 80M;

    # SSL证书配置
    ssl_certificate /www/server/panel/vhost/cert/coinspay.xyz/fullchain.pem;
    ssl_certificate_key /www/server/panel/vhost/cert/coinspay.xyz/privkey.pem;
    ssl_protocols TLSv1.1 TLSv1.2 TLSv1.3;
    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE;
    ssl_prefer_server_ciphers on;
    ssl_session_cache shared:SSL:10m;
    ssl_session_timeout 10m;

    location / {
        try_files $uri $uri/ /index.php$is_args$query_string;
    }

    location = /favicon.ico { access_log off; log_not_found off; }
    location = /robots.txt  { access_log off; log_not_found off; }

    error_page 404 /index.php;

    location ~ \.php$ {
        fastcgi_pass unix:/tmp/php-cgi-81.sock;
        fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name;
        fastcgi_param HTTPS on; # 告知Laravel当前使用HTTPS协议
        include fastcgi_params;
    }

    location ~ /\.ht {
        deny all;
    }

    location /socket.io {
        proxy_pass https://localhost:6001;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-Proto https; # 传递HTTPS协议头给后端服务
        proxy_cache_bypass $http_upgrade;
    }
}

# 可选:强制HTTP跳转HTTPS
server {
    listen 80;
    listen [::]:80;
    server_name coinspay.xyz;
    return 301 https://$server_name$request_uri;
}

2. 确保Laravel正确识别HTTPS

  • 确认.env中APP_URL=https://coinspay.xyz已设置
  • 在app/Providers/AppServiceProvider.php的boot方法中添加强制HTTPS规则(生产环境):
public function boot()
{
    if (env('APP_ENV') === 'production') {
        \URL::forceScheme('https');
    }
}

3. 修复文件权限问题

执行以下命令设置项目目录正确权限:

chown -R www:www /www/wwwroot/coinspay.xyz
chmod -R 755 /www/wwwroot/coinspay.xyz
chmod -R 644 /www/wwwroot/coinspay.xyz/public/*

4. 验证配置并重启服务

  1. 检查Nginx配置语法:nginx -t
  2. 重启Nginx:service nginx restart
  3. 清除Laravel缓存:php artisan config:clear && php artisan cache:clear
  4. 清空浏览器缓存后重新访问HTTPS站点

内容的提问来源于stack exchange,提问作者AskSEOTools

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 14:22:02