使用nginx ngx_http_auth_request_module时ModSecurity返回403如何解决
问题解决办法
问题根本原因
你遇到的问题根源是两点:
- ModSecurity默认会处理NGINX的所有内部子请求,
ngx_http_auth_request_module生成的/auth子请求也会被校验 - 你在
location /auth中配置的proxy_set_header Content-Length ""是作用于转发给上游认证服务的请求头,ModSecurity处理子请求的时机早于代理转发阶段,拿到的还是原始POST请求的Content-Length值,子请求默认用GET方法,就触发了920170号规则。
以下是按推荐优先级排序的解决方案:
方案1(最推荐):关闭/auth路径的ModSecurity校验
/auth是internal属性的路径,仅能被NGINX内部调用,外部请求无法直接访问,完全不需要WAF防护,直接关闭即可。
修改你的/auth location配置:
location /auth { internal; # 新增以下两行关闭ModSecurity modsecurity off; SecRuleEngine Off; proxy_pass_request_body off; proxy_set_header Content-Length ""; proxy_set_header access_token $http_access_token; proxy_pass http://authentication-gwy:8080/cmr-experience-serv-gateway-loggin/v1/auth/token-valid; }
配置完成后重载NGINX即可生效。
方案2:仅排除触发拦截的指定规则
如果你需要保留/auth路径的ModSecurity校验,仅排除920170号规则即可,直接在location /auth块中添加规则排除:
location /auth { internal; # 排除触发拦截的920170号规则 SecRuleRemoveById 920170; proxy_pass_request_body off; proxy_set_header Content-Length ""; proxy_set_header access_token $http_access_token; proxy_pass http://authentication-gwy:8080/cmr-experience-serv-gateway-loggin/v1/auth/token-valid; }
方案3:修正子请求的Content-Length输入头
如果你的NGINX安装了headers-more模块,可以直接修改子请求本身的输入头,让ModSecurity拿到正确的空Content-Length值:
location /auth { internal; # 修改输入请求的Content-Length头,ModSecurity可识别该修改 more_set_input_headers "Content-Length: "; proxy_pass_request_body off; proxy_set_header Content-Length ""; proxy_set_header access_token $http_access_token; proxy_pass http://authentication-gwy:8080/cmr-experience-serv-gateway-loggin/v1/auth/token-valid; }
内容的提问来源于stack exchange,提问作者JYGS
相关产品推荐
相关产品推荐

