如何在IIS重写/反向代理中允许携带utm_source、utm_medium参数
IIS反向代理携带utm_source/utm_medium参数访问报错问题
问题描述
我在Windows Server 2016和IIS中搭建了反向代理,整体运行正常,仅存在以下异常:
- 无法正常访问格式为
https://mywebsite/shop/product/3231?utm_source=IGShopping&utm_medium=Social的URL - 将URL中的
utm_source修改为utm_sour等其他字符时,访问恢复正常 - 直接通过localhost访问上述带utm参数的URL可正常打开
- 仅当URL携带
utm_source和utm_medium参数时才会触发报错
现有配置参考
web.config配置内容如下:
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <rewrite> <outboundRules> <clear /> <rule name="Add SameSite" preCondition="No SameSite"> <match serverVariable="RESPONSE_Set_Cookie" pattern=".*" negate="false" /> <action type="Rewrite" value="{R:0}; SameSite=None; Secure" /> </rule> <rule name="ReverseProxyOutboundRule1" preCondition="ResponseIsHtml1" enabled="true"> <match filterByTags="A, Form, Img" pattern="^http(s)?://localhost:8068/(.*)" /> <action type="Rewrite" value="http{R:1}://mocauae.ae/{R:2}" /> </rule> <preConditions> <preCondition name="ResponseIsHtml1"> <add input="{RESPONSE_CONTENT_TYPE}" pattern="^text/html" /> </preCondition> <preCondition name="No SameSite"> <add input="{RESPONSE_Set_Cookie}" pattern="." /> <add input="{RESPONSE_Set_Cookie}" pattern="; SameSite=None; Secure" negate="true" /> </preCondition> </preConditions> </outboundRules> <rules> <rule name="ReverseProxyInboundRule1" enabled="true" stopProcessing="true"> <match url="(.*)" /> <action type="Rewrite" url="http://localhost:8068/{R:1}" /> </rule> <rule name="HTTPS" enabled="false" patternSyntax="Wildcard" stopProcessing="true"> <match url="*" /> <conditions> <add input="{HTTPS}" pattern="off" /> </conditions> <action type="Redirect" url="http://localhost:8068" redirectType="Found" /> </rule> <rule name="HTTPS force" enabled="false" stopProcessing="true"> <match url="(.*)" /> <conditions> <add input="{HTTPS}" pattern="^OFF$" /> </conditions> <action type="Redirect" url="https://localhost:8068" appendQueryString="false" redirectType="Permanent" /> </rule> <rule name="https pure" enabled="false" patternSyntax="Wildcard" stopProcessing="true"> <match url="*" /> <action type="Redirect" url="https://localhost:8068" redirectType="Found" /> <conditions> <add input="{HTTP}" pattern="off" /> </conditions> </rule> </rules> </rewrite> <httpRedirect enabled="false" destination="http://localhost:8068" exactDestination="true" /> </system.webServer> </configuration>
修复方案
问题根因
当前问题由两个配置缺陷共同导致:
- 入站反向代理规则未显式开启查询字符串透传,特殊参数传递出现截断
- IIS默认请求过滤规则拦截了
utm_*开头的营销类查询参数,请求在到达重写规则前就被拒绝
操作步骤
- 修改反向代理入站规则,开启参数透传
找到ReverseProxyInboundRule1规则,添加appendQueryString="true"属性:
<rule name="ReverseProxyInboundRule1" enabled="true" stopProcessing="true"> <match url="(.*)" /> <action type="Rewrite" url="http://localhost:8068/{R:1}" appendQueryString="true" /> </rule>
- 放行utm系列查询参数
在web.config的<system.webServer>节点下新增如下配置,跳过请求过滤对utm参数的拦截:
<security> <requestFiltering> <alwaysAllowedQueryStrings> <add queryString="utm_source" /> <add queryString="utm_medium" /> <add queryString="utm_campaign" /> <add queryString="utm_term" /> <add queryString="utm_content" /> </alwaysAllowedQueryStrings> </requestFiltering> </security>
- 保存配置后重启IIS站点,重新测试带utm参数的链接即可正常访问。
内容的提问来源于stack exchange,提问作者Rana
相关产品推荐
相关产品推荐

