如何限制Laravel项目仅本地访问并隐藏框架信息(Windows Server+Apache环境)
Hey there, let's work through your Apache virtual host configuration to meet all your requirements. First, let's recap your setup so we're aligned:
环境概况
- 操作系统:Microsoft Windows Server
- Web服务器:Apache
- 前端框架:Vue.js
- 后端框架:Laravel
当前配置现状
Your current httpd-vhost.conf looks like this:
<VirtualHost *:80> DocumentRoot "C:\Apache24\htdocs\index" ServerName example.com <Directory "C:\Apache24\htdocs\index"> Options Indexes FollowSymLinks AllowOverride All Require all granted </Directory> </VirtualHost> <VirtualHost *:9999> DocumentRoot "C:\Apache24\htdocs\Laravel_project_name\public" ServerName example.com <Directory "C:\Apache24\htdocs\Laravel_project_name\public"> Options FollowSymLinks AllowOverride All Require all granted </Directory> </VirtualHost>
需求对应解决方案
Let's break down each requirement and apply the necessary changes step by step:
1. Allow any IP to access example.com
Your existing port 80 virtual host already uses Require all granted, which fully covers this requirement. No changes needed here—we'll keep this intact in the final config.
2. Restrict example.com:9999 to local access only
Replace the Require all granted line in the port 9999 virtual host's <Directory> block with Require local. This rule automatically allows both IPv4 (127.0.0.1) and IPv6 (::1) local connections. If you want to be explicit, you can also use:
Require ip 127.0.0.1 ::1
3. Hide your framework and server information
To keep your tech stack under wraps, we need to tweak two key areas:
- Apache server headers: Edit your main
httpd.conffile to add these lines (you can also add them inside each virtual host block for per-host control):# Hide Apache version and detailed server info ServerTokens Prod ServerSignature Off # Remove X-Powered-By header (which may expose PHP/Laravel) Header unset X-Powered-By - Vue.js framework hints: Update your
vue.config.jsto setproductionSourceMap: false—this disables source maps that could reveal Vue's code structure. Also, remove any public meta tags or comments that explicitly mention Vue.js.
4. Block external access to Laravel public directory files
Since we're already restricting port 9999 to local access, external users can't reach this directory at all. To add an extra layer of security (in case of misconfiguration), add a <FilesMatch> block inside the Laravel virtual host's <Directory> section to restrict sensitive file types to local access only:
<FilesMatch "\.(php|html|txt|css|js)$"> Require local </FilesMatch>
Final httpd-vhost.conf Configuration
Here's the complete updated config that meets all your requirements:
<VirtualHost *:80> DocumentRoot "C:\Apache24\htdocs\index" ServerName example.com <Directory "C:\Apache24\htdocs\index"> Options Indexes FollowSymLinks AllowOverride All Require all granted </Directory> # Hide headers for frontend too Header unset X-Powered-By </VirtualHost> <VirtualHost *:9999> DocumentRoot "C:\Apache24\htdocs\Laravel_project_name\public" ServerName example.com <Directory "C:\Apache24\htdocs\Laravel_project_name\public"> Options FollowSymLinks AllowOverride All # Restrict entire directory to local access Require local # Extra security: Lock down specific file types <FilesMatch "\.(php|html|txt|css|js)$"> Require local </FilesMatch> </Directory> Header unset X-Powered-By </VirtualHost>
Additional Tips
- Restart Apache after making these changes for them to take effect.
- Ensure your Laravel
.envfile setsAPP_DEBUG=falsein production—this prevents sensitive framework details from leaking in error pages. - If you can't edit
httpd.conf, move theServerTokensandServerSignaturelines into each<VirtualHost>block (global config is cleaner, though).
内容的提问来源于stack exchange,提问作者hua

