解决NGINX优先返回本地index.html而非代理至后端IIS的问题
解决方案
针对你的需求,只需在现有NGINX配置中添加两个location块即可解决问题,无需改动原有结构:
upstream my_backend { server 10.10.10.102:1011; include snippets/shared_upstream_settings.conf; } server { listen 443 ssl http2; listen [::]:443 ssl http2; server_name server.mydomain.com; include snippets/shared_server_proxy_settings.conf; location @proxy { proxy_pass http://my_backend; } # 新增:处理根路径跳转至免责声明页 location = / { satisfy any; allow 10.16.0.0/24; deny all; auth_basic "Authorized Users Only"; auth_basic_user_file secure/.htpasswd; auth_request /auth-1; return 301 $scheme://$host/default.htm; } # 新增:强制代理/index.html请求至后端,跳过本地文件检查 location = /index.html { satisfy any; allow 10.16.0.0/24; deny all; auth_basic "Authorized Users Only"; auth_basic_user_file secure/.htpasswd; auth_request /auth-1; proxy_pass http://my_backend; } location / { satisfy any; allow 10.16.0.0/24; deny all; auth_basic "Authorized Users Only"; auth_basic_user_file secure/.htpasswd; auth_request /auth-1; try_files $uri @proxy; } }
配置说明
- 根路径跳转:
location = /精确匹配用户仅输入域名的请求,通过return 301重定向到IIS上的default.htm,确保用户先访问免责声明页。 - 强制代理/index.html:
location = /index.html精确匹配直接访问/index.html的请求,跳过NGINX本地文件检查逻辑,直接将请求代理至后端IIS,解决硬编码链接无法正确转发的问题。 - 两个新增
location块复制了原有location /的权限认证配置,保证权限校验逻辑一致,不破坏原有站点的安全规则。
内容的提问来源于stack exchange,提问作者BenH
相关产品推荐
相关产品推荐

