IIS反向代理Tomcat部署XWiki时部分URL报500错误求助
IIS反向代理XWiki时部分URL返回500错误的排查与解决
问题背景
已部署XWiki实例,通过IIS作为反向代理指向运行XWiki的Tomcat服务器。部分URL通过IIS访问时出现500错误,但直接访问Tomcat对应的URL则正常运行,推测是IIS Rewrite模块配置问题。
错误URL示例
https://mywikiurl.com/rest/liveData/sources/liveTable/entries?timestamp=1659037220812&namespace=wiki%3Axwiki&sourceParams.resultPage=XWiki.LoggingAdminTableJson&sourceParams.translationPrefix=logging.admin.livetable.&sourceParams.queryFilters=currentlanguage%2Chidden&properties=logger&properties=level&properties=actions&offset=0&limit=15&sort=logger&descending=
直接访问Tomcat的正常URL
http://mytomcat_server_fqdn:8080/xwiki/rest/liveData/sources/liveTable/entries?timestamp=1659037220812&namespace=wiki%3Axwiki&sourceParams.resultPage=XWiki.LoggingAdminTableJson&sourceParams.translationPrefix=logging.admin.livetable.&sourceParams.queryFilters=currentlanguage%2Chidden&properties=logger&properties=level&properties=actions&offset=0&limit=15&sort=logger&descending=
当前配置
IIS web.config配置
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <rewrite> <rules useOriginalURLEncoding="false"> <clear /> <rule name="Redirect to Https" patternSyntax="Wildcard" stopProcessing="true"> <match url="*" /> <conditions logicalGrouping="MatchAll" trackAllCaptures="false"> <add input="{HTTPS}" pattern="off" /> </conditions> <action type="Redirect" url="https://{HTTP_HOST}{REQUEST_URI}" redirectType="Found" /> </rule> <rule name="ReverseProxyInboundRule1" stopProcessing="true"> <match url="(.*)" /> <conditions logicalGrouping="MatchAll" trackAllCaptures="false"> <add input="{UNENCODED_URL}" pattern="/(.*)" /> </conditions> <action type="Rewrite" url="http://mytomcat_server_fqdn:8080/{C:1}" logRewrittenUrl="false" /> </rule> </rules> <outboundRules> <preConditions> <preCondition name="ResponseIsHtml1"> <add input="{RESPONSE_CONTENT_TYPE}" pattern="^text/html" /> </preCondition> </preConditions> </outboundRules> </rewrite> <security> <requestFiltering allowDoubleEscaping="true"> <requestLimits maxAllowedContentLength="3521478366" /> <hiddenSegments> <remove segment="bin" /> </hiddenSegments> </requestFiltering> </security> </system.webServer> <system.web> <httpRuntime requestPathInvalidCharacters="" relaxedUrlToFileSystemMapping="true"/> <authentication mode="Windows" /> <identity impersonate="false" /> </system.web> </configuration>
Tomcat server.xml修改部分
<Connector port="8080" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="8443" compression="on" compressableMimeType= "text/html,text/xml,text/plain,text/css,text/javascript,application/javascript"> </Connector> <Engine name="Catalina" defaultHost="localhost"> <Valve className="org.apache.catalina.valves.RemoteIpValve" internalProxies="127\.0\.[0-1]\.1" remoteIpHeader="x-forwarded-for" requestAttributesEnabled="true" protocolHeader="x-forwarded-proto" protocolHeaderHttpsValue="https"></Valve> . . . </Engine>
问题排查与解决方案
1. 修复路径映射缺失问题
观察正常URL可知,Tomcat端的请求路径包含/xwiki/前缀,但当前Rewrite规则直接转发IIS请求路径到Tomcat,未添加该前缀,导致请求指向Tomcat的根路径而非XWiki部署路径。
修改反向代理规则:
<rule name="ReverseProxyInboundRule1" stopProcessing="true"> <match url="(.*)" /> <!-- 移除多余的UNENCODED_URL条件,避免路径解析异常 --> <action type="Rewrite" url="http://mytomcat_server_fqdn:8080/xwiki/{R:1}" logRewrittenUrl="true" /> </rule>
- 新增
/xwiki/前缀,匹配Tomcat上XWiki的实际部署路径 - 使用
{R:1}替代{C:1},确保完整保留请求路径与查询参数 - 开启
logRewrittenUrl="true",便于排查转发后的URL是否正确
2. 调整URL编码设置
当前规则设置useOriginalURLEncoding="false",可能导致IIS对URL进行二次编码,与Tomcat的预期编码格式冲突。将其改为true以保留原始编码:
<rules useOriginalURLEncoding="true">
3. 添加必要的请求头转发
XWiki可能依赖请求头判断请求来源,需在反向代理中转发关键头信息。在<rewrite>节点下添加允许修改的服务器变量:
<rewrite> <allowedServerVariables> <add name="HTTP_X_FORWARDED_HOST" /> <add name="HTTP_X_FORWARDED_PORT" /> <add name="HTTP_X_FORWARDED_PROTO" /> </allowedServerVariables> <!-- 现有rules和outboundRules --> </rewrite>
然后在反向代理规则的<action>后添加变量设置:
<action type="Rewrite" url="http://mytomcat_server_fqdn:8080/xwiki/{R:1}" logRewrittenUrl="true" /> <serverVariables> <set name="HTTP_X_FORWARDED_HOST" value="{HTTP_HOST}" /> <set name="HTTP_X_FORWARDED_PORT" value="{SERVER_PORT}" /> <set name="HTTP_X_FORWARDED_PROTO" value="{HTTPS}" /> </serverVariables>
4. 验证Tomcat RemoteIpValve配置
如果IIS与Tomcat不在同一台服务器,需将IIS的IP地址添加到internalProxies列表中,确保Tomcat识别代理请求:
<Valve className="org.apache.catalina.valves.RemoteIpValve" internalProxies="127\.0\.[0-1]\.1|192\.168\.1\.100" <!-- 替换为IIS服务器的实际IP --> remoteIpHeader="x-forwarded-for" requestAttributesEnabled="true" protocolHeader="x-forwarded-proto" protocolHeaderHttpsValue="https"></Valve>
测试步骤
- 修改web.config后,重启IIS站点
- 访问之前报错的URL,验证是否恢复正常
- 查看IIS日志与Tomcat的
access.log,确认转发后的URL是否包含/xwiki/前缀 - 若仍报错,查看Tomcat的
localhost.log或XWiki日志,获取具体的500错误详情
内容的提问来源于stack exchange,提问作者Andy Johnson
相关产品推荐
相关产品推荐

