Apache服务器index.php后接不存在目录未返回404问题排查
Apache EC2实例URL路径错误问题解决
问题描述
在运行Amazon Linux的Amazon EC2实例上部署Apache服务器时,访问类似https://example.com/index.php/some-directory或https://example.com/about/index.php/some-directory的URL时,未返回预期的404错误,反而加载了父目录的内容(例如第二个示例中混乱加载about目录内容)。
期望结果
上述URL请求应返回404错误页面。
已尝试步骤
- 检查
.conf和.htaccess配置,未发现错误配置项 - 添加
AcceptPathInfo Off禁用路径信息解析,问题仍存在 - 在
.htaccess和httpd.conf中添加-MultiViews指令关闭多视图选项,问题未解决
当前.htaccess核心配置
<IfModule mod_headers.c> <Files *.mp4> Header set Accept-Ranges bytes </Files> </IfModule> # Enable Compression <IfModule mod_deflate.c> AddOutputFilterByType DEFLATE application/javascript AddOutputFilterByType DEFLATE application/rss+xml AddOutputFilterByType DEFLATE application/vnd.ms-fontobject AddOutputFilterByType DEFLATE application/x-font AddOutputFilterByType DEFLATE application/x-font-opentype AddOutputFilterByType DEFLATE application/x-font-otf AddOutputFilterByType DEFLATE application/x-font-truetype AddOutputFilterByType DEFLATE application/x-font-ttf AddOutputFilterByType DEFLATE application/x-javascript AddOutputFilterByType DEFLATE application/xhtml+xml AddOutputFilterByType DEFLATE application/xml AddOutputFilterByType DEFLATE font/opentype AddOutputFilterByType DEFLATE font/otf AddOutputFilterByType DEFLATE font/ttf AddOutputFilterByType DEFLATE image/svg+xml AddOutputFilterByType DEFLATE image/x-icon AddOutputFilterByType DEFLATE text/css AddOutputFilterByType DEFLATE text/html AddOutputFilterByType DEFLATE text/javascript AddOutputFilterByType DEFLATE text/plain </IfModule> <IfModule mod_gzip.c> mod_gzip_on Yes mod_gzip_dechunk Yes mod_gzip_item_include file .(html?|txt|css|js|php|pl)$ mod_gzip_item_include handler ^cgi-script$ mod_gzip_item_include mime ^text/.* mod_gzip_item_include mime ^application/x-javascript.* mod_gzip_item_exclude mime ^image/.* mod_gzip_item_exclude rspheader ^Content-Encoding:.*gzip.* </IfModule> # Leverage Browser Caching <IfModule mod_expires.c> ExpiresActive On ExpiresByType image/jpg "access 1 day" ExpiresByType image/jpeg "access 1 day" ExpiresByType image/gif "access 1 years" ExpiresByType image/webp "access 1 day" ExpiresByType image/png "access 1 years" ExpiresByType text/css "access 1 day" ExpiresByType text/html "access 10 minute" ExpiresByType application/pdf "access 1 week" ExpiresByType text/x-javascript "access 1 day" ExpiresByType application/x-shockwave-flash "access 1 years" ExpiresByType image/x-icon "access 1 years" ExpiresDefault "access 1 day" </IfModule> <IfModule mod_headers.c> <filesmatch "\.(ico|flv|jpg|jpeg|png|gif|css|swf|svg|mp4|mpeg|webp|woff2|ttf)$"> Header set Cache-Control "max-age=86400, public" </filesmatch> <filesmatch "\.(html|htm|php)$"> Header set Cache-Control "max-age=600, public, must-revalidate" </filesmatch> <filesmatch "\.(pdf)$"> Header set Cache-Control "max-age=86400, public" </filesmatch> <filesmatch "\.(js)$"> Header set Cache-Control "max-age=86400, public" </filesmatch> </IfModule> ErrorDocument 300 /404/index.php ErrorDocument 403 /404/index.php ErrorDocument 404 /404/index.php Options +FollowSymLinks RewriteEngine On #Allow for case-flexible directories #The mod_speling module must be activated within the EC2 server itself prior to this working <IfModule mod_speling.c> CheckSpelling On CheckCaseOnly On </IfModule> <IfModule mod_brotli.c> AddOutputFilterByType BROTLI_COMPRESS text/html text/plain text/xml text/css text/javascript application/javascript </IfModule> RewriteEngine On # match any URL with www and rewrite it to https without the www RewriteCond %{HTTP_HOST} ^(www\.)(.*) [NC] RewriteRule (.*) https://%2%{REQUEST_URI} [L,R=301] # match urls that are non https (without the www) RewriteCond %{HTTPS} off RewriteCond %{HTTP_HOST} !^(www\.)(.*) [NC] RewriteRule (.*) https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
解决方案
核心原因
Apache默认会将index.php/xxx这类URL中的/xxx作为PATH_INFO传递给PHP脚本,若PHP未处理该PATH_INFO逻辑,会直接执行index.php本身,导致加载父目录内容而非返回404。
具体修复步骤
- 添加Rewrite规则拦截无效路径
在.htaccess的RewriteEngine On之后(建议放在HTTPS重写规则之前)添加以下规则:
# 拦截PHP文件后带额外路径的请求,直接返回404 RewriteRule ^(.+\.php)/ - [R=404,L]
此规则会匹配所有以.php结尾且后续带有/的URL,直接返回404状态码。
- 调整PHP配置强化拦截
编辑php.ini文件(通常路径为/etc/php.ini或/etc/php/<版本>/apache2/php.ini),确保以下配置:
cgi.fix_pathinfo=0
该配置会禁用PHP对PATH_INFO的自动解析,避免Apache将无效路径传递给PHP脚本。修改后重启Apache服务:
sudo systemctl restart httpd
- 验证修复效果
访问之前的测试URL(如https://example.com/index.php/test),确认页面返回404错误。
内容的提问来源于stack exchange,提问作者Jonathan LeRoux
相关产品推荐
相关产品推荐

