Nginx配置Shopware开发环境BasicAuth:排除/admin及/api路径遇异常
问题:Shopware开发环境Nginx BasicAuth配置异常
需求:在Shopware开发环境中配置BasicAuth,阻止谷歌爬虫及普通访客访问站点,仅放行/admin和/api路径(避免SPA后端Ajax请求频繁触发登录提示)。
遇到的问题:配置后访问/admin仍弹出密码验证框,即使在/admin location中添加auth_basic off; allow all;也无效。
原配置代码:
server { listen [--IP--]:80; listen [--IP--]:443 ssl http2; ssl_protocols TLSv1.2 TLSv1.3; ssl_certificate /var/www/clients/client1/web7/ssl/[--DOMAIN--].crt; ssl_certificate_key /var/www/clients/client1/web7/ssl/[--DOMAIN--].key; server_name [--DOMAIN--] ; root /var/www/[--DOMAIN--]/web; . . . add_header X-Robots-Tag "noindex, nofollow" always; location @rewriteapp { root /var/www/[--DOMAIN--]/web/public/; client_max_body_size 100M; rewrite ^/(.*)$ /index.php last; } location /admin { alias /var/www/[--DOMAIN--]/web/public/; client_max_body_size 100M; index index.php; http2_push_preload on; rewrite ^/(.+)\.php/(.*)$ /$1.php last; try_files $uri @rewriteapp; location ~ \.php$ { try_files $uri =404; include /etc/nginx/fastcgi_params; fastcgi_index index.php; . . . http2_push_preload on; } } location / { alias /var/www/[--DOMAIN--]/web/public/; client_max_body_size 100M; index index.php; http2_push_preload on; rewrite ^/(.+)\.php/(.*)$ /$1.php last; try_files $uri @rewriteapp; . . . auth_basic "DEV"; auth_basic_user_file /var/www/clients/client1/web6/web/public/.htpasswd; location ~ \.php$ { try_files $uri =404; include /etc/nginx/fastcgi_params; fastcgi_index index.php; . . . http2_push_preload on; } }
解决方案
问题原因
Nginx的location匹配优先级是前缀匹配(如/admin)先于通用前缀/,但你的/admin块里用了try_files $uri @rewriteapp;,当请求的/admin下资源不存在时,会跳转到@rewriteapp,而@rewriteapp最终会匹配到/ location下的index.php,此时/ location中的BasicAuth规则就会生效,导致弹出验证框。
另外,你之前在/admin里加的auth_basic off只作用于该location本身,无法覆盖后续跳转的/ location的规则。
正确配置思路
- 先定义不需要验证的路径:
/admin、/api,直接放行 - 对所有其他请求统一应用BasicAuth
- 调整跳转逻辑,避免绕过规则
修改后的配置
server { listen [--IP--]:80; listen [--IP--]:443 ssl http2; ssl_protocols TLSv1.2 TLSv1.3; ssl_certificate /var/www/clients/client1/web7/ssl/[--DOMAIN--].crt; ssl_certificate_key /var/www/clients/client1/web7/ssl/[--DOMAIN--].key; server_name [--DOMAIN--] ; root /var/www/[--DOMAIN--]/web/public/; # 直接将根目录设到public,简化路径匹配 add_header X-Robots-Tag "noindex, nofollow" always; # 统一放行/admin和/api路径,关闭BasicAuth location ~ ^/(admin|api) { client_max_body_size 100M; index index.php; http2_push_preload on; rewrite ^/(.+)\.php/(.*)$ /$1.php last; try_files $uri $uri/ /index.php$is_args$args; location ~ \.php$ { try_files $uri =404; include /etc/nginx/fastcgi_params; fastcgi_index index.php; # 保留你原有的fastcgi配置内容 http2_push_preload on; } auth_basic off; allow all; } # 所有其他请求强制应用BasicAuth location / { client_max_body_size 100M; index index.php; http2_push_preload on; rewrite ^/(.+)\.php/(.*)$ /$1.php last; try_files $uri $uri/ /index.php$is_args$args; auth_basic "DEV"; auth_basic_user_file /var/www/clients/client1/web6/web/public/.htpasswd; location ~ \.php$ { try_files $uri =404; include /etc/nginx/fastcgi_params; fastcgi_index index.php; # 保留你原有的fastcgi配置内容 http2_push_preload on; } } # 移除原@rewriteapp,逻辑已整合到各location中 # location @rewriteapp { # rewrite ^/(.*)$ /index.php last; # }
关键修改点
- 将server的
root直接指向/web/public/,避免alias带来的路径匹配歧义 - 用正则匹配
^/(admin|api)统一处理两个放行路径,明确关闭BasicAuth规则 - 调整
try_files逻辑,直接指向index.php,避免跳转到@rewriteapp触发通用location的验证 - 确保放行路径下的PHP请求也继承
auth_basic off的规则,不会被其他location覆盖
内容的提问来源于stack exchange,提问作者Stahlkocher
相关产品推荐
相关产品推荐

