Apache 2.4表单登录:错误凭证后登录跳转异常问题
Apache 2.4 LDAP表单认证重试跳转问题解决
核心问题
登录失败跳转至badlogin.shtml后,再次提交正确凭证时,原请求的目标URI未被正确传递,导致登录成功后默认跳转到登录处理页do-login.html,触发302错误和"Method Not Allowed"提示。
解决配置方案
1. 受保护目录配置(httpd.conf)
在<Directory>段中添加环境变量捕获逻辑,保留原请求URI:
<Directory "/var/www/html/private"> AuthType form AuthName "LDAP Protected Area" AuthFormProvider ldap AuthLDAPURL "ldap://your-ldap-server:389/ou=users,dc=example,dc=com?uid?sub?(objectClass=inetOrgPerson)" AuthLDAPBindDN "cn=admin,dc=example,dc=com" AuthLDAPBindPassword "your-ldap-password" Require valid-user # 捕获首次请求的URI到环境变量 SetEnvIf Request_URI "^/private/.*" ORIGINAL_REQUEST=%{REQUEST_URI} # 从badlogin的Referer中提取原请求URI,覆盖环境变量 SetEnvIf Referer "badlogin\.shtml\?req=(.*)" ORIGINAL_REQUEST=$1 # 登录页传递原请求参数 AuthFormLoginRequiredLocation "/login.html?req=%{ENV:ORIGINAL_REQUEST}" # 登录成功优先跳转到原请求URI,无值时用默认页 AuthFormLoginSuccessLocation "%{ENV:ORIGINAL_REQUEST}/private/index.shtml" </Directory>
2. 错误登录页(badlogin.shtml)调整
确保表单携带原请求的req参数,用SSI获取环境变量:
<form method="post" action="/do-login.html"> <!-- 隐藏字段传递原请求URI --> <input type="hidden" name="req" value="<!--#echo var="ORIGINAL_REQUEST" -->"> <label>用户名:<input type="text" name="username"></label> <label>密码:<input type="password" name="password"></label> <button type="submit">重新登录</button> </form>
注意:需启用mod_include模块,并在badlogin.shtml所在目录添加Options +Includes配置。
3. 登录处理页(do-login.html)权限配置
确保允许POST方法处理登录请求:
<Location "/do-login.html"> AuthType form AuthName "LDAP Protected Area" AuthFormProvider ldap AuthLDAPURL "ldap://your-ldap-server:389/ou=users,dc=example,dc=com?uid?sub?(objectClass=inetOrgPerson)" AuthLDAPBindDN "cn=admin,dc=example,dc=com" AuthLDAPBindPassword "your-ldap-password" Require valid-user # 仅允许POST方法访问登录处理页 AllowMethods POST </Location>
关键逻辑说明
- 首次访问受保护资源时,
SetEnvIf捕获原URI存入ORIGINAL_REQUEST,登录页通过req参数传递该值。 - 登录失败跳转至
badlogin.shtml时,页面通过SSI读取环境变量,表单提交时再次携带req参数,SetEnvIf从Referer中提取该值更新环境变量。 - 登录成功时,
AuthFormLoginSuccessLocation优先使用环境变量中的原URI跳转,避免默认跳转到处理页。
内容的提问来源于stack exchange,提问作者Roger McCarrick
相关产品推荐
相关产品推荐

