You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Apache 2.4表单登录:错误凭证后登录跳转异常问题

Apache 2.4 LDAP表单认证重试跳转问题解决

核心问题

登录失败跳转至badlogin.shtml后,再次提交正确凭证时,原请求的目标URI未被正确传递,导致登录成功后默认跳转到登录处理页do-login.html,触发302错误和"Method Not Allowed"提示。

解决配置方案

1. 受保护目录配置(httpd.conf)

在<Directory>段中添加环境变量捕获逻辑,保留原请求URI:

<Directory "/var/www/html/private">
    AuthType form
    AuthName "LDAP Protected Area"
    AuthFormProvider ldap
    AuthLDAPURL "ldap://your-ldap-server:389/ou=users,dc=example,dc=com?uid?sub?(objectClass=inetOrgPerson)"
    AuthLDAPBindDN "cn=admin,dc=example,dc=com"
    AuthLDAPBindPassword "your-ldap-password"
    Require valid-user

    # 捕获首次请求的URI到环境变量
    SetEnvIf Request_URI "^/private/.*" ORIGINAL_REQUEST=%{REQUEST_URI}
    # 从badlogin的Referer中提取原请求URI,覆盖环境变量
    SetEnvIf Referer "badlogin\.shtml\?req=(.*)" ORIGINAL_REQUEST=$1

    # 登录页传递原请求参数
    AuthFormLoginRequiredLocation "/login.html?req=%{ENV:ORIGINAL_REQUEST}"
    # 登录成功优先跳转到原请求URI,无值时用默认页
    AuthFormLoginSuccessLocation "%{ENV:ORIGINAL_REQUEST}/private/index.shtml"
</Directory>

2. 错误登录页(badlogin.shtml)调整

确保表单携带原请求的req参数,用SSI获取环境变量:

<form method="post" action="/do-login.html">
    <!-- 隐藏字段传递原请求URI -->
    <input type="hidden" name="req" value="<!--#echo var="ORIGINAL_REQUEST" -->">
    <label>用户名:<input type="text" name="username"></label>
    <label>密码:<input type="password" name="password"></label>
    <button type="submit">重新登录</button>
</form>

注意:需启用mod_include模块,并在badlogin.shtml所在目录添加Options +Includes配置。

3. 登录处理页(do-login.html)权限配置

确保允许POST方法处理登录请求:

<Location "/do-login.html">
    AuthType form
    AuthName "LDAP Protected Area"
    AuthFormProvider ldap
    AuthLDAPURL "ldap://your-ldap-server:389/ou=users,dc=example,dc=com?uid?sub?(objectClass=inetOrgPerson)"
    AuthLDAPBindDN "cn=admin,dc=example,dc=com"
    AuthLDAPBindPassword "your-ldap-password"
    Require valid-user

    # 仅允许POST方法访问登录处理页
    AllowMethods POST
</Location>

关键逻辑说明

  • 首次访问受保护资源时,SetEnvIf捕获原URI存入ORIGINAL_REQUEST,登录页通过req参数传递该值。
  • 登录失败跳转至badlogin.shtml时,页面通过SSI读取环境变量,表单提交时再次携带req参数,SetEnvIf从Referer中提取该值更新环境变量。
  • 登录成功时,AuthFormLoginSuccessLocation优先使用环境变量中的原URI跳转,避免默认跳转到处理页。

内容的提问来源于stack exchange,提问作者Roger McCarrick

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 05:47:37