基于外部服务实现Nginx指定静态页面的身份认证配置求助
Alright, let's walk through how to set this up properly—since auth_basic isn't an option, Nginx's auth_request module is your perfect solution here. It lets you offload authentication checks to your REST server before granting access to the /secret path.
auth_request module First, make sure your Nginx installation includes this module. Run this command to check:
nginx -V | grep auth_request
If you see --with-http_auth_request_module in the output, you're good to go. If not, you'll need to recompile Nginx with this flag or use a pre-built package that includes it.
Here's the full server block configuration tailored to your setup. I'll break down each part so you understand what's happening:
server { listen 80; server_name www.somesite.com; # Path to your static HTML/CSS/JS files root /var/www/somesite/static; index index.html; # Protect the /secret path location /secret { # Trigger the authentication check before serving content auth_request /auth-check; # Serve static files if authentication passes try_files $uri $uri/ =404; # Handle authentication failures error_page 401 = @auth-failed; } # Internal endpoint for delegating auth to your REST server location = /auth-check { internal; # Block direct external access to this endpoint proxy_pass http://your-rest-server-ip:port/api/verify-token; # Pass critical client headers to the REST server for token validation proxy_pass_header Authorization; proxy_set_header Cookie $http_cookie; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; # Don't send the original request body to the auth server (unnecessary here) proxy_pass_request_body off; proxy_set_header Content-Length ""; } # Define what happens when authentication fails location @auth-failed { # Option 1: Redirect users to your REST server's login page return 302 http://your-rest-server-ip:port/login?redirect=$request_uri; # Option 2: Return a custom 401 JSON response (uncomment if preferred) # return 401 '{"error": "Access denied. Please log in first."}'; # add_header Content-Type application/json; } }
What each part does:
auth_request /auth-check: Tells Nginx to run an internal request to/auth-checkbefore processing any request to/secret. If that internal request returns a 200, access is allowed; if it returns 401, access is blocked.internal: Ensures the/auth-checkendpoint can only be called by Nginx itself, not external users.proxy_pass: Forwards the auth check request to your REST server's token validation endpoint. Adjust the URL to match your actual REST API path.- Header forwarding: Passes the client's token (stored either in an
Authorizationheader or a cookie) to the REST server so it can validate the user's identity. @auth-failed: Handles failed authentication—either redirect to login or return a custom error, depending on your use case.
Your REST server needs a token validation endpoint (like /api/verify-token) that:
- Extracts the user's access token from either the
Authorizationheader (e.g.,Bearer <token>) or a cookie. - Validates the token's signature, expiration date, and any required permissions.
- Returns an HTTP 200 status code if the token is valid.
- Returns an HTTP 401 status code if the token is invalid, expired, or missing.
- Secure communication: If your Nginx server and REST server are on separate machines, use HTTPS for the
proxy_passURL (e.g.,https://your-rest-server-ip:port/api/verify-token) to prevent token interception. - Caching (optional): To reduce load on your REST server, you can cache valid authentication results. Just be sure the cache duration is shorter than your token's expiration time to avoid serving stale auth statuses.
- Custom token locations: If your token is stored in a custom header (not
Authorizationor a cookie), add aproxy_set_headerline to pass it to the REST server (e.g.,proxy_set_header X-Auth-Token $http_x_auth_token;).
内容的提问来源于stack exchange,提问作者ivan

