You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用nginx ngx_http_auth_request_module时ModSecurity返回403如何解决

问题解决办法

问题根本原因

你遇到的问题根源是两点:

  1. ModSecurity默认会处理NGINX的所有内部子请求,ngx_http_auth_request_module生成的/auth子请求也会被校验
  2. 你在location /auth中配置的proxy_set_header Content-Length ""是作用于转发给上游认证服务的请求头,ModSecurity处理子请求的时机早于代理转发阶段,拿到的还是原始POST请求的Content-Length值,子请求默认用GET方法,就触发了920170号规则。

以下是按推荐优先级排序的解决方案:

方案1(最推荐):关闭/auth路径的ModSecurity校验

/auth是internal属性的路径,仅能被NGINX内部调用,外部请求无法直接访问,完全不需要WAF防护,直接关闭即可。
修改你的/auth location配置:

location /auth {
  internal;
  # 新增以下两行关闭ModSecurity
  modsecurity off;
  SecRuleEngine Off;

  proxy_pass_request_body off;
  proxy_set_header Content-Length "";
  proxy_set_header access_token $http_access_token;
  proxy_pass http://authentication-gwy:8080/cmr-experience-serv-gateway-loggin/v1/auth/token-valid;
}

配置完成后重载NGINX即可生效。

方案2:仅排除触发拦截的指定规则

如果你需要保留/auth路径的ModSecurity校验,仅排除920170号规则即可,直接在location /auth块中添加规则排除:

location /auth {
  internal;
  # 排除触发拦截的920170号规则
  SecRuleRemoveById 920170;

  proxy_pass_request_body off;
  proxy_set_header Content-Length "";
  proxy_set_header access_token $http_access_token;
  proxy_pass http://authentication-gwy:8080/cmr-experience-serv-gateway-loggin/v1/auth/token-valid;
}

方案3:修正子请求的Content-Length输入头

如果你的NGINX安装了headers-more模块,可以直接修改子请求本身的输入头,让ModSecurity拿到正确的空Content-Length值:

location /auth {
  internal;
  # 修改输入请求的Content-Length头,ModSecurity可识别该修改
  more_set_input_headers "Content-Length: ";

  proxy_pass_request_body off;
  proxy_set_header Content-Length "";
  proxy_set_header access_token $http_access_token;
  proxy_pass http://authentication-gwy:8080/cmr-experience-serv-gateway-loggin/v1/auth/token-valid;
}

内容的提问来源于stack exchange,提问作者JYGS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.24 02:54:03