You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx配置Shopware开发环境BasicAuth:排除/admin及/api路径遇异常

问题:Shopware开发环境Nginx BasicAuth配置异常

需求:在Shopware开发环境中配置BasicAuth,阻止谷歌爬虫及普通访客访问站点,仅放行/admin和/api路径(避免SPA后端Ajax请求频繁触发登录提示)。

遇到的问题:配置后访问/admin仍弹出密码验证框,即使在/admin location中添加auth_basic off; allow all;也无效。

原配置代码:

server {
listen [--IP--]:80;
listen [--IP--]:443 ssl http2;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_certificate /var/www/clients/client1/web7/ssl/[--DOMAIN--].crt;
ssl_certificate_key /var/www/clients/client1/web7/ssl/[--DOMAIN--].key;

server_name [--DOMAIN--] ;
root /var/www/[--DOMAIN--]/web;

.
.
.

add_header X-Robots-Tag "noindex, nofollow" always;

location @rewriteapp {
    root /var/www/[--DOMAIN--]/web/public/;
    client_max_body_size 100M;
    rewrite ^/(.*)$ /index.php last;
}

location /admin {
    alias /var/www/[--DOMAIN--]/web/public/;
    client_max_body_size 100M;
    index index.php;
    http2_push_preload on;

    rewrite ^/(.+)\.php/(.*)$ /$1.php last;

    try_files $uri @rewriteapp;

    location ~ \.php$ {
        try_files $uri =404;
        include /etc/nginx/fastcgi_params;
        fastcgi_index index.php;
        .
        .
        .
        http2_push_preload on;
    }
}

location / {
    alias /var/www/[--DOMAIN--]/web/public/;
    client_max_body_size 100M;
    index index.php;
    http2_push_preload on;

    rewrite ^/(.+)\.php/(.*)$ /$1.php last;

    try_files $uri @rewriteapp;

    .
    .
    .

    auth_basic "DEV";
    auth_basic_user_file /var/www/clients/client1/web6/web/public/.htpasswd;

    location ~ \.php$ {
        try_files $uri =404;
        include /etc/nginx/fastcgi_params;
        fastcgi_index index.php;
        .
        .
        .
        http2_push_preload on;
    }
}

解决方案

问题原因

Nginx的location匹配优先级是前缀匹配(如/admin)先于通用前缀/,但你的/admin块里用了try_files $uri @rewriteapp;,当请求的/admin下资源不存在时,会跳转到@rewriteapp,而@rewriteapp最终会匹配到/ location下的index.php,此时/ location中的BasicAuth规则就会生效,导致弹出验证框。

另外,你之前在/admin里加的auth_basic off只作用于该location本身,无法覆盖后续跳转的/ location的规则。

正确配置思路

  1. 先定义不需要验证的路径:/admin、/api,直接放行
  2. 对所有其他请求统一应用BasicAuth
  3. 调整跳转逻辑,避免绕过规则

修改后的配置

server {
listen [--IP--]:80;
listen [--IP--]:443 ssl http2;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_certificate /var/www/clients/client1/web7/ssl/[--DOMAIN--].crt;
ssl_certificate_key /var/www/clients/client1/web7/ssl/[--DOMAIN--].key;

server_name [--DOMAIN--] ;
root /var/www/[--DOMAIN--]/web/public/;  # 直接将根目录设到public,简化路径匹配

add_header X-Robots-Tag "noindex, nofollow" always;

# 统一放行/admin和/api路径,关闭BasicAuth
location ~ ^/(admin|api) {
    client_max_body_size 100M;
    index index.php;
    http2_push_preload on;

    rewrite ^/(.+)\.php/(.*)$ /$1.php last;
    try_files $uri $uri/ /index.php$is_args$args;

    location ~ \.php$ {
        try_files $uri =404;
        include /etc/nginx/fastcgi_params;
        fastcgi_index index.php;
        # 保留你原有的fastcgi配置内容
        http2_push_preload on;
    }

    auth_basic off;
    allow all;
}

# 所有其他请求强制应用BasicAuth
location / {
    client_max_body_size 100M;
    index index.php;
    http2_push_preload on;

    rewrite ^/(.+)\.php/(.*)$ /$1.php last;
    try_files $uri $uri/ /index.php$is_args$args;

    auth_basic "DEV";
    auth_basic_user_file /var/www/clients/client1/web6/web/public/.htpasswd;

    location ~ \.php$ {
        try_files $uri =404;
        include /etc/nginx/fastcgi_params;
        fastcgi_index index.php;
        # 保留你原有的fastcgi配置内容
        http2_push_preload on;
    }
}

# 移除原@rewriteapp,逻辑已整合到各location中
# location @rewriteapp {
#     rewrite ^/(.*)$ /index.php last;
# }

关键修改点

  • 将server的root直接指向/web/public/,避免alias带来的路径匹配歧义
  • 用正则匹配^/(admin|api)统一处理两个放行路径,明确关闭BasicAuth规则
  • 调整try_files逻辑,直接指向index.php,避免跳转到@rewriteapp触发通用location的验证
  • 确保放行路径下的PHP请求也继承auth_basic off的规则,不会被其他location覆盖

内容的提问来源于stack exchange,提问作者Stahlkocher

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 05:55:30