Laravel应用HTTP正常运行,HTTPS访问报403错误求助
Laravel应用HTTPS访问403错误排查与解决
问题描述
HTTP协议下Laravel应用可正常运行,但HTTPS访问时页面空白,控制台报错:
Failed to load resource: the server responded with a status of 403 ()
已配置SSL证书,HTTP/HTTPS链接均可访问,但仅HTTP版本能正常加载数据。
环境信息
- 操作系统:Ubuntu 22.04
- 主机面板:aaPanel
- Web服务器:Nginx
已配置内容
Laravel .env配置
APP_NAME='TradeWithShine Exchange' APP_ENV=production APP_KEY=base64:PqJTkxOD1loJIUnMtvkhmKLYTa/NFbsJtkQR0dxaQx8= APP_DEBUG=false APP_URL=https://coinspay.xyz SANCTUM_STATEFUL_DOMAINS="coinspay.xyz" LOG_CHANNEL=stack TRADE_FREQUENCY=10 USER_ASSETS="false" USER_ASSETS_HASH="1708829973402"
当前Nginx主配置(业务站点部分)
server { listen 80; root /www/wwwroot/coinspay.xyz/public; index index.php index.html index.htm; server_name coinspay.xyz; client_max_body_size 80M; location / { try_files $uri $uri/ /index.php$is_args$query_string; } location = /favicon.ico { access_log off; log_not_found off; } location = /robots.txt { access_log off; log_not_found off; } error_page 404 /index.php; location ~ \.php$ { fastcgi_pass unix:/tmp/php-cgi-81.sock; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; include fastcgi_params; } location ~ /\.ht { deny all; } location /socket.io { proxy_pass https://localhost:6001; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_cache_bypass $http_upgrade; } }
排查与解决步骤
1. 补充HTTPS站点Nginx配置
当前仅配置了80端口的HTTP站点,缺失443端口的HTTPS配置块。添加以下配置(替换证书路径为aaPanel生成的实际路径):
server { listen 443 ssl http2; listen [::]:443 ssl http2; root /www/wwwroot/coinspay.xyz/public; index index.php index.html index.htm; server_name coinspay.xyz; client_max_body_size 80M; # SSL证书配置 ssl_certificate /www/server/panel/vhost/cert/coinspay.xyz/fullchain.pem; ssl_certificate_key /www/server/panel/vhost/cert/coinspay.xyz/privkey.pem; ssl_protocols TLSv1.1 TLSv1.2 TLSv1.3; ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE; ssl_prefer_server_ciphers on; ssl_session_cache shared:SSL:10m; ssl_session_timeout 10m; location / { try_files $uri $uri/ /index.php$is_args$query_string; } location = /favicon.ico { access_log off; log_not_found off; } location = /robots.txt { access_log off; log_not_found off; } error_page 404 /index.php; location ~ \.php$ { fastcgi_pass unix:/tmp/php-cgi-81.sock; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; fastcgi_param HTTPS on; # 告知Laravel当前使用HTTPS协议 include fastcgi_params; } location ~ /\.ht { deny all; } location /socket.io { proxy_pass https://localhost:6001; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection 'upgrade'; proxy_set_header Host $host; proxy_set_header X-Forwarded-Proto https; # 传递HTTPS协议头给后端服务 proxy_cache_bypass $http_upgrade; } } # 可选:强制HTTP跳转HTTPS server { listen 80; listen [::]:80; server_name coinspay.xyz; return 301 https://$server_name$request_uri; }
2. 确保Laravel正确识别HTTPS
- 确认
.env中APP_URL=https://coinspay.xyz已设置 - 在
app/Providers/AppServiceProvider.php的boot方法中添加强制HTTPS规则(生产环境):
public function boot() { if (env('APP_ENV') === 'production') { \URL::forceScheme('https'); } }
3. 修复文件权限问题
执行以下命令设置项目目录正确权限:
chown -R www:www /www/wwwroot/coinspay.xyz chmod -R 755 /www/wwwroot/coinspay.xyz chmod -R 644 /www/wwwroot/coinspay.xyz/public/*
4. 验证配置并重启服务
- 检查Nginx配置语法:
nginx -t - 重启Nginx:
service nginx restart - 清除Laravel缓存:
php artisan config:clear && php artisan cache:clear - 清空浏览器缓存后重新访问HTTPS站点
内容的提问来源于stack exchange,提问作者AskSEOTools
相关产品推荐
相关产品推荐

