MVC站点URL含末尾双点触发403 Forbidden错误求助
解决方案
方案1:配置IIS请求过滤允许末尾点
IIS默认请求过滤规则会拦截包含末尾点的请求,这是触发403错误的核心原因。在web.config的<system.webServer>节点下添加以下配置,放行查询字符串中的末尾双点:
<system.webServer> <security> <requestFiltering allowDoubleEscaping="true"> <requestLimits allowQueryStringDoubleDot="true" /> </requestFiltering> </security> </system.webServer>
其中allowQueryStringDoubleDot="true"专门针对查询字符串的双点放行,allowDoubleEscaping确保特殊字符不会被额外拦截。
方案2:用URL重写自动清理末尾双点
如果不想修改请求过滤规则,可通过IIS URL重写模块自动修正带末尾双点的查询字符串。在web.config的<system.webServer>中添加重写规则:
<system.webServer> <rewrite> <rules> <rule name="Remove Trailing Double Dots in Query String" stopProcessing="true"> <match url="(.*)" /> <conditions> <add input="{QUERY_STRING}" pattern="^(.*)\.\.$" /> </conditions> <action type="Redirect" url="{R:0}?{C:1}" redirectType="Permanent" /> </rule> </rules> </rewrite> </system.webServer>
该规则会将查询字符串末尾的双点替换为单点,避免触发IIS的拦截逻辑。
方案3:自定义HTTP模块修改请求
若上述方案不适用,可编写简单的HTTP模块,在请求到达MVC路由前修改查询字符串:
public class CleanQueryStringModule : IHttpModule { public void Init(HttpApplication context) { context.BeginRequest += Context_BeginRequest; } private void Context_BeginRequest(object sender, EventArgs e) { var app = (HttpApplication)sender; var queryString = app.Request.QueryString.ToString(); if (!string.IsNullOrEmpty(queryString) && queryString.EndsWith("..")) { var cleanedQuery = queryString.Substring(0, queryString.Length - 1); app.Context.RewritePath(app.Request.Path, app.Request.PathInfo, cleanedQuery); } } public void Dispose() { } }
随后在web.config的<system.web>中注册模块:
<system.web> <httpModules> <add name="CleanQueryStringModule" type="YourNamespace.CleanQueryStringModule, YourAssembly" /> </httpModules> </system.web>
如果是IIS集成模式,还需在<system.webServer>中补充注册:
<system.webServer> <modules> <add name="CleanQueryStringModule" type="YourNamespace.CleanQueryStringModule, YourAssembly" preCondition="managedHandler" /> </modules> </system.webServer>
补充说明
你之前尝试的relaxedUrlToFileSystemMapping配置仅针对URL路径与文件系统映射的场景,对查询字符串的限制规则无效,因此无法解决当前问题。
内容的提问来源于stack exchange,提问作者Brian Salta
相关产品推荐
相关产品推荐

