You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为何含分号的URL绕过Nginx的/actuator/路径访问限制?

问题原因分析

1. URI规范化导致location匹配失效

Nginx默认开启uri_normalization on,会对请求URI进行规范化处理,包括解析路径中的../、合并连续斜杠等。当请求/actuator/prometheus;%2f..%2f..//到达时:

  • 首先被URL解码为/actuator/prometheus;/../../;
  • Nginx将分号后的/../../识别为路径的一部分,规范化后整个路径被简化为/;
  • 此时location /actuator/的前缀匹配不再生效,请求转而匹配优先级更低的location /,绕过了IP限制规则。

2. 无错误日志的原因

因为请求最终匹配的是location /,该规则没有deny限制,直接代理到后端,所以不会触发403错误,自然也不会生成错误日志。

调试方法
  • 开启调试日志追踪匹配过程
    在Nginx的http块中添加以下配置,重启后重新发送请求,查看调试日志可明确URI处理和location匹配的每一步:

    debug_connection 你的客户端IP或IP段;
    error_log /var/log/nginx/debug.log debug;
    
  • 添加自定义响应头验证匹配结果
    修改两个location块,分别添加唯一标识的响应头,发送请求后查看响应头即可确认请求匹配的是哪个location:

    location /actuator/ {
        add_header X-Matched-Location "actuator-restricted";
        allow 10.1.1.0/24;
        deny all;
        proxy_pass http://10.1.1.1:8989;
    }   
    
    location / {
        add_header X-Matched-Location "root-unrestricted";
        proxy_pass http://10.1.1.1:8989;
    }
    
  • 临时关闭URI规范化验证猜想
    在/actuator/的location块中临时添加uri_normalization off,重新发送请求,若此时触发403,则可确认是规范化导致的匹配失效:

    location /actuator/ {
        uri_normalization off;
        allow 10.1.1.0/24;
        deny all;
        proxy_pass http://10.1.1.1:8989;
    }
    

内容的提问来源于stack exchange,提问作者Doodle-loo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 02:35:16