You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu环境下Nginx Secure Link配置持续返回403错误求助

问题描述

在Ubuntu系统中配置Nginx Secure Link后,访问生成的链接始终返回403错误,无法播放视频。

Nginx服务器配置

server {
    listen  80;
    server_name server.test.com;

    location /t/ {
       alias /home/server/files/;
     }

    location /y {
    proxy_set_header X-Real-Ip $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header Host $host;
    proxy_set_header REMOTE_ADDR $remote_addr;
    sendfile on;
    tcp_nopush on;
    alias /home/server/files/;
    # set connection secure link
    secure_link $arg_st,$arg_e;
    secure_link_md5 "itsaSSEEECRET$uri$secure_link_expires$remote_addr";

    # bad hash
    if ($secure_link = "") {
        return 403;
    }

    # link expired
    if ($secure_link = "0") {
        return 410;
    }

    # do something useful here
}
}

生成链接的Python代码

import base64
import hashlib
import calendar
import datetime

secret = "itsaSSEEECRET"
url = "/y/test.mp4"
ip = "XXX.XXX.XXX.XXX"

future = datetime.datetime.utcnow() + datetime.timedelta(minutes=5)
expiry = calendar.timegm(future.timetuple())

secure_link = f"{secret}{url}{expiry}{ip}".encode('utf-8')

hash = hashlib.md5(secure_link).digest()
base64_hash = base64.urlsafe_b64encode(hash)
str_hash = base64_hash.decode('utf-8').rstrip('=')

print(f"http://server.test.com{url}?st={str_hash}&e={expiry}")

可能的问题及解决方法

  • IP地址不匹配:
    Python代码中ip变量必须是访问客户端的真实公网IP(本地测试填127.0.0.1)。若服务器在反向代理后,$remote_addr会获取代理IP而非客户端IP,此时需将secure_link_md5中的IP变量改为$http_x_real_ip或$http_x_forwarded_for,同时确保代理已正确传递客户端IP头。

  • 文件权限不足:
    检查Nginx运行用户(通常为www-data)是否有权读取目标视频文件。执行以下命令修正权限:

    chmod 644 /home/server/files/test.mp4
    chmod 755 /home/server/files/
    
  • location路径解析异常:
    当前location /y未以/结尾,但alias以/结尾,可能导致路径映射错误。建议将location改为/y/,Python代码中的url保持/y/test.mp4不变,确保Nginx能正确定位到文件。

  • 验证字符串拼接不一致:
    确认Nginx配置中secure_link_md5的拼接顺序与Python代码完全一致:secret + $uri + $secure_link_expires + $remote_addr,避免多余空格或特殊字符,引号需正确包裹整段字符串。

  • Nginx版本不兼容:
    secure_link模块在Nginx 1.7.10及以上版本默认启用,若版本过低,需升级Nginx或编译时添加--with-http_secure_link_module参数。

内容的提问来源于stack exchange,提问作者Paul Mark

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.24 23:24:56