You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx重写规则配置:如何避免非指定PHP文件被直接执行?

Hey there, let's sort out this Nginx rewrite problem you're stuck on! The core issue here is Nginx's location matching priority—you need to explicitly allow the safe paths/files first, block unauthorized PHP execution, and then apply your rewrite rule. Here's a step-by-step solution that should fix your config.php bypass issue:

Key Configuration Breakdown

We'll structure the rules in order of Nginx's matching priority (highest to lowest) to ensure nothing slips through:

  1. Exact match for loader.php
    This ensures loader.php is always executed directly, without being caught by other rules.

    location = /loader.php {
        include fastcgi_params;
        fastcgi_pass unix:/var/run/php/php7.4-fpm.sock; # Update to your PHP-FPM socket/path
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
    }
    
  2. Priority match for /images/ directory
    Using ^~ tells Nginx to prioritize this prefix match over any regular expression locations, so all requests under /images/ are served normally—including PHP files inside this directory if needed.

    location ^~ /images/ {
        root /path/to/your/webroot; # Replace with your actual website root directory
        
        # Uncomment below if you need to execute PHP files inside /images/
        location ~ \.php$ {
            include fastcgi_params;
            fastcgi_pass unix:/var/run/php/php7.4-fpm.sock;
            fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        }
    }
    
  3. Block all other PHP files
    This rule catches any PHP request that wasn't matched by the above two rules, preventing direct execution of files like config.php.

    location ~ \.php$ {
        deny all;
        return 403; # Optional: Returns a "Forbidden" error instead of just blocking
    }
    
  4. Rewrite all remaining requests
    Finally, any request that isn't for loader.php or under /images/ gets rewritten to your loader script.

    location / {
        rewrite ^/(.*)$ /loader.php?control=$1 last;
    }
    

Why This Works

Your original issue happened because Nginx was matching the regular expression rule for .php files before your rewrite rule. By ordering the rules from highest priority (exact/prefix matches) to lowest, we:

  • First allow the safe files/directory
  • Block all other PHP execution
  • Then apply the rewrite for everything else

Quick Testing Steps

  1. Validate your config with nginx -t to catch syntax errors
  2. Reload Nginx with systemctl reload nginx (or service nginx reload depending on your OS)
  3. Test accessing yourdomain.com/config.php—it should now return a 403 instead of executing the file, while yourdomain.com/anything-else gets rewritten to loader.php?control=anything-else

内容的提问来源于stack exchange,提问作者J. Smith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:03:16