无需include及allow_url_include,嵌入外部PHP文件的HTML输出方案
替代方案汇总(无需修改
allow_url_include) 嘿,我给你整理几个不用碰allow_url_include的靠谱方案,都是直接拿目标页面的浏览器输出,完全不用执行对方的PHP代码:
1. PHP后端用file_get_contents()(最简单的后端方案)
这个方法直接请求远程URL并获取返回的HTML内容,只要服务器开启了allow_url_fopen(这个默认大多是开启的,而且比allow_url_include安全得多)就能用。
示例代码:
<?php // 获取远程页面的HTML输出 $remoteHtml = file_get_contents('https://www.site1.com/script.php'); // 可选:如果遇到请求被拦截,可以模拟浏览器请求头 // $context = stream_context_create([ // 'http' => [ // 'header' => 'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36' // ] // ]); // $remoteHtml = file_get_contents('https://www.site1.com/script.php', false, $context); ?> <!-- 把内容放到你的div里,自定义CSS类 --> <div class="custom-remote-content"> <?php echo $remoteHtml; ?> </div>
2. PHP后端用cURL(更灵活的后端方案)
如果file_get_contents遇到限制(比如对方服务器拦截了默认请求头),cURL是更好的选择,它支持自定义请求头、处理HTTPS、设置超时等,可控性更强。
示例代码:
<?php $ch = curl_init(); // 设置目标URL curl_setopt($ch, CURLOPT_URL, 'https://www.site1.com/script.php'); // 让返回结果以字符串形式返回,而不是直接输出 curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // 模拟浏览器User-Agent,避免被拦截 curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36'); // 处理HTTPS(生产环境建议开启证书验证,这里为了简化暂时关闭) curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); // 设置超时时间(可选) curl_setopt($ch, CURLOPT_TIMEOUT, 10); $remoteHtml = curl_exec($ch); // 检查请求是否成功 if(curl_errno($ch)){ $remoteHtml = '加载远程内容失败:' . curl_error($ch); } curl_close($ch); ?> <div class="custom-remote-content"> <?php echo $remoteHtml; ?> </div>
3. 前端AJAX请求(无需后端处理)
如果不想在后端操作,可以用前端异步请求获取内容,再插入到目标div里。不过要注意跨域问题:如果两个网站域名不同,目标服务器需要配置CORS(Access-Control-Allow-Origin)响应头,否则浏览器会拦截请求。
jQuery版本示例:
<div id="remote-content-container" class="custom-remote-content"></div> <script src="https://code.jquery.com/jquery-3.7.1.min.js"></script> <script> $(document).ready(function() { // 发起GET请求获取远程HTML $.get('https://www.site1.com/script.php') .done(function(htmlContent) { // 把内容插入到div中 $('#remote-content-container').html(htmlContent); }) .fail(function() { $('#remote-content-container').text('抱歉,内容加载失败'); }); }); </script>
原生JS版本示例:
<div id="remote-content-container" class="custom-remote-content"></div> <script> document.addEventListener('DOMContentLoaded', function() { const container = document.getElementById('remote-content-container'); const xhr = new XMLHttpRequest(); xhr.open('GET', 'https://www.site1.com/script.php'); xhr.onload = function() { if (xhr.status === 200) { container.innerHTML = xhr.responseText; } else { container.textContent = '内容加载失败,状态码:' + xhr.status; } }; xhr.onerror = function() { container.textContent = '网络请求失败'; }; xhr.send(); }); </script>
4. 使用iframe(快速但样式控制有限)
如果对样式控制要求不高,直接用iframe嵌入远程页面是最省事的方法,不过iframe里的内容会继承原页面的CSS,要修改样式可能需要额外处理(比如原页面配合或者用postMessage通信),而且对SEO不太友好。
示例代码:
<!-- 嵌入远程页面到iframe --> <iframe src="https://www.site1.com/script.php" class="remote-content-iframe" frameborder="0"></iframe> <style> /* 自定义iframe样式 */ .remote-content-iframe { width: 100%; height: 600px; border: none; border-radius: 8px; box-shadow: 0 2px 8px rgba(0,0,0,0.1); } </style>
重要注意事项:
- 安全风险:不管用哪种方法,都要注意过滤远程内容,防止XSS攻击!如果只允许特定标签(比如
<h2>、<p>),可以用strip_tags保留允许的标签:// 只保留<h2>、<p>标签,过滤其他所有标签 $safeHtml = strip_tags($remoteHtml, '<h2><p>'); - 跨域问题:后端方法不受浏览器同源策略限制,所以没有跨域问题;前端方法必须确保目标服务器允许跨域请求。
内容的提问来源于stack exchange,提问作者Hunterwolf
相关产品推荐
相关产品推荐

