You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

开启Basic Auth后Nginx反向代理S3存储桶异常问题求助

Nginx反向代理Linode对象存储时Basic Auth登录后400错误解决

问题背景

我用Nginx反向代理Linode的S3兼容对象存储桶,原本无Basic Auth的配置可以正常运行,但添加Basic Auth后出现异常。

正常运行的无Basic Auth配置

location /api {
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com/api;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
}

location /images {
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com/images;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
}

location / {
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
}

添加Basic Auth后的异常配置

location /api {
        auth_basic off; # 新增
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com/api;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_ignore_headers    Authorization; # 新增
        proxy_hide_header    Authorization; # 新增
}

location /images {
        auth_basic off; # 新增
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com/images;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_ignore_headers    Authorization; # 新增
        proxy_hide_header    Authorization; # 新增
}

location / {
        auth_basic           "Restricted Access"; # 新增
        auth_basic_user_file {MY_PATH_HERE};  # 新增
    
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_ignore_headers    Authorization; # 新增
        proxy_hide_header    Authorization; # 新增
}

问题现象

  • Basic Auth验证逻辑正常:访问/需要输入密码,/api和/images无需验证;
  • 未登录时访问/api/api.json能得到有效响应;
  • 登录Basic Auth后,所有端点均返回400错误。

曾尝试用proxy_ignore_headers Authorization和proxy_hide_header Authorization屏蔽请求头,但无效果。

调试信息

  • 未开启Basic Auth时,浏览器发给Nginx的请求头无authorization字段;
  • 开启并登录Basic Auth后,请求头新增一行:authorization: Basic somekeyhere。

补充信息:域名通过Cloudflare解析,已跳过该子域名的防护。

解决方案

问题出在你用错了Nginx指令:proxy_ignore_headers是忽略后端返回的响应头,proxy_hide_header是隐藏后端返回给客户端的响应头,都无法处理客户端发送过来的Authorization请求头。正确的做法是清空转发给Linode对象存储的Authorization请求头,使用proxy_set_header Authorization "";指令。

修改后的完整配置

location /api {
        auth_basic off;
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com/api;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Authorization ""; # 新增:清空请求头
}

location /images {
        auth_basic off;
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com/images;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Authorization ""; # 新增:清空请求头
}

location / {
        auth_basic           "Restricted Access";
        auth_basic_user_file {MY_PATH_HERE};
    
        proxy_http_version 1.1;
        proxy_pass https://mydomainhere.eu-central-1.linodeobjects.com;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header Authorization ""; # 新增:清空请求头
}

说明

proxy_set_header Authorization ""会将客户端发送的Authorization请求头清空,不会转发给Linode对象存储。Linode S3兼容存储收到无效的Auth头时会返回400错误,清空后就不会触发这个问题,同时不影响Nginx自身的Basic Auth验证逻辑。

内容的提问来源于stack exchange,提问作者Solonl

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 07:15:02