如何在Django中为域名添加前缀实现会员专属子域名访问
Alright, let's walk through exactly how to build this custom subdomain dashboard feature for your members. I’ve implemented this for a handful of SaaS and membership sites, so here’s the step-by-step breakdown that works in production:
The foundation here is making sure any subdomain (like jane.mysite.com or john.mysite.com) points to your web server. To do this, you’ll need to add a wildcard A record in your domain’s DNS settings:
- In your domain registrar’s control panel, create a new A record with the host value
* - Point it to your server’s public IP address
This tells DNS servers that any subdomain undermysite.comshould route to your server.
Next, your web server needs to recognize these subdomains and pass the prefix to your application. Let’s cover the two most common servers:
Nginx Example
Update your Nginx server block to listen for all subdomains, then extract the prefix:
server { listen 80; listen 443 ssl; server_name *.mysite.com; # Extract subdomain prefix (e.g., "jane" from jane.mysite.com) set $subdomain ""; if ($host ~* "^(.*)\.mysite\.com$") { set $subdomain $1; } # Pass the subdomain to your app via a custom header or FastCGI param location / { proxy_pass http://your-app-server; proxy_set_header X-Subdomain $subdomain; # Or for PHP-FPM: fastcgi_param SUBDOMAIN $subdomain; } # Don't forget your wildcard SSL cert here for HTTPS ssl_certificate /path/to/wildcard.mysite.com.crt; ssl_certificate_key /path/to/wildcard.mysite.com.key; }
Apache Example
Use a VirtualHost with a wildcard ServerAlias, then rewrite the subdomain into a query parameter:
<VirtualHost *:80> ServerAlias *.mysite.com DocumentRoot /var/www/mysite/public RewriteEngine On # Extract subdomain and pass it to the app RewriteCond %{HTTP_HOST} ^(.*)\.mysite\.com$ [NC] RewriteRule ^(.*)$ /index.php?subdomain=%1 [L,QSA] # For HTTPS, duplicate this in a <VirtualHost *:443> block with your wildcard SSL cert </VirtualHost>
Now your app needs to take the subdomain prefix, map it to a member, and load their dashboard. Let’s use a PHP example (the logic translates to Node.js, Python, etc.):
// Get the subdomain from the header or query parameter $subdomain = $_SERVER['HTTP_X_SUBDOMAIN'] ?? $_GET['subdomain'] ?? ''; // Skip reserved prefixes (don't let users take www, admin, api, etc.) $reservedPrefixes = ['www', 'admin', 'api', 'mail', 'ftp']; if (in_array(strtolower($subdomain), $reservedPrefixes)) { header("HTTP/1.1 404 Not Found"); exit; } // Look up the member in your database by their subdomain prefix $member = $db->query("SELECT * FROM members WHERE subdomain_prefix = ?", [$subdomain])->fetch(); if (!$member) { // No member found for this subdomain - redirect to home or show 404 header("Location: https://www.mysite.com"); exit; } // Now load the member's dashboard using their ID or data loadMemberDashboard($member['id']);
Add a unique field to your members table to store their subdomain prefix:
ALTER TABLE members ADD COLUMN subdomain_prefix VARCHAR(50) UNIQUE NOT NULL;
When a member signs up:
- Let them choose a prefix (or auto-generate one from their username, lowercase, no special chars)
- Validate that the prefix isn’t reserved or already taken
- Save it to the
subdomain_prefixfield
Don’t skip these—they prevent abuse and bugs:
- Reserved Prefixes: Block users from taking subdomains like
adminorapito avoid conflicts with your main site’s services. - Wildcard SSL Cert: Get a wildcard SSL certificate (Let’s Encrypt offers these for free) to secure all subdomains. Browsers will warn users if you use HTTP for subdomains.
- Cross-Subdomain Security: Make sure your session cookies are configured correctly—don’t allow sessions to be shared across subdomains unless intentional. Use
SameSite=Strictand set the cookie domain to.mysite.comonly if needed. - Subdomain-Member Match: Even if someone types a valid subdomain, ensure the currently logged-in user (if any) matches the member associated with that subdomain. Prevent users from accessing another member’s dashboard by just typing their subdomain.
- Let members update their subdomain prefix (with re-validation for uniqueness)
- Add a preview tool during sign-up so users can see what their subdomain will look like
- Redirect old subdomains to new ones if a member changes theirs
- Add a "parked" state for deleted members’ subdomains to prevent squatting
内容的提问来源于stack exchange,提问作者Bigga

