NGINX配置IP子目录部署Laravel出现403错误求助
Laravel部署在Nginx下出现403错误的排查与解决
问题场景
尝试在http://176.99.4.205/front/部署Laravel,先后编写了两个Nginx站点配置,但均出现403错误:
初始配置
server { listen 80; listen [::]:80; server_name example.com; root /home/vbulash/nginx.html; index index.html index.php; charset utf-8; access_log off; location / { try_files $uri $uri/ /index.php?$query_string; } location ^~ /front { allow all; alias /home/vbulash/nginx.html/front/public; index index.php; location ~ \.php$ { allow all; if (!-f $request_filename) { return 404; } fastcgi_pass unix:/var/run/php/php8.2-fpm.sock; fastcgi_param SCRIPT_FILENAME $realpath_root$fastcgi_script_name; include fastcgi_params; } } location ~ /\.(?!well-known).* { deny all; } error_log /var/log/nginx/front.site.error.log; }
调整后的配置
location /front { alias /home/vbulash/nginx.html/front/public; try_files $uri $uri/ @front; location ~ \.php$ { fastcgi_split_path_info ^(.+\.php)(/.+)$; fastcgi_pass unix:/var/run/php/php8.2-fpm.sock; fastcgi_index index.php; include fastcgi_params; fastcgi_param SCRIPT_FILENAME $request_filename; } } location @front { rewrite /front/(.*)$ /front/index.php last; }
问题排查与解决
403错误核心原因要么是权限不足,要么是Nginx无法定位到正确文件,以下是具体排查点和修复方案:
1. 优先检查目录与文件权限
这是最常见的403诱因:
- 确保Nginx运行用户(通常是
www-data或nginx)对/home/vbulash/nginx.html/front/public及其所有父目录拥有读权限,目录本身需要执行权限(用于遍历目录) - 执行以下命令修复权限(根据实际运行用户调整):
chmod -R 755 /home/vbulash/nginx.html/front/public chown -R www-data:www-data /home/vbulash/nginx.html/front
2. 初始配置的问题点
location ^~ /front块缺少try_files规则,当访问/front/时,Nginx尝试访问public目录但未自动转发到index.php,若目录未开启autoindex就会返回403$realpath_root$fastcgi_script_name在alias场景下路径计算容易出错,改用$request_filename能更准确指向实际文件路径
3. 调整后配置的问题点
@front中的rewrite规则有问题,重写后的路径无法正确映射到public目录下的index.php,导致Nginx找不到文件返回403- 缺少对PHP文件存在性的校验,容易触发无效请求
修正后的完整配置
server { listen 80; listen [::]:80; server_name example.com; root /home/vbulash/nginx.html; index index.html index.php; charset utf-8; access_log off; location / { try_files $uri $uri/ /index.php?$query_string; } location /front { alias /home/vbulash/nginx.html/front/public; # 优先访问静态文件,不存在则转发到index.php try_files $uri $uri/ /front/index.php?$query_string; location ~ \.php$ { # 校验文件是否存在,避免无效请求 if (!-f $request_filename) { return 404; } fastcgi_pass unix:/var/run/php/php8.2-fpm.sock; # 准确指定PHP脚本路径 fastcgi_param SCRIPT_FILENAME $request_filename; include fastcgi_params; } } location ~ /\.(?!well-known).* { deny all; } error_log /var/log/nginx/front.site.error.log; }
额外排查步骤
- 查看Nginx错误日志
/var/log/nginx/front.site.error.log,日志会明确标注403的具体原因(比如权限拒绝、文件不存在) - 确认PHP-FPM的运行用户是否拥有目标目录的访问权限,避免PHP进程无法读取Laravel文件
内容的提问来源于stack exchange,提问作者vbulash
相关产品推荐
相关产品推荐

