我正在尝试通过 Nginx 网络服务器 proxy_pass 从 example.com/blog 为我的 Wordpress 网站提供服务,并将其传输到托管在 blog.site.com 的另一台服务器上的 Wordpress 网站(apache)。
使用我当前的 Nginx 配置,从 site.com/blog 查看博客工作正常,但是,我无法访问 Wordpress 网站的登录信息。似乎它可能落入了 ~. .php 位置,但我不确定如何防止这种行为。
例如,当我尝试https://example.com/blog/wp-admin它返回 404https://example.com/wp-admin/
如果我尝试https://example.com/blog/wp-admin/它给了我一个没有指定输入文件的 stdErrhttps://example.com/blog/wp-login.php?redirect_to=https%3A%2F%2Fexample.com%2Fblog%2Fwp-admin%2F&reauth=1
example.com 的 Nginx 配置 -
map $uri $expires {
default off;
~\.(jpg|jpeg|png|gif|ico|css|js|pdf)$ 7d;
}
server {
listen 443 ssl http2;
listen [::]:443 ssl http2;
server_name site.com;
root /var/www/example.com/current/public;
ssl_certificate /etc/nginx/ssl/site.com/454191/server.crt;
ssl_certificate_key /etc/nginx/ssl/site.com/454191/server.key;
ssl_protocols TLSv1.2;
ssl_ciphers ECDHE-RSA-AES256-GCM-SHA512:DHE-RSA-AES256-GCM-SHA512:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384;
ssl_prefer_server_ciphers on;
ssl_dhparam /etc/nginx/dhparams.pem;
add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options "nosniff";
index index.html index.htm index.php;
charset utf-8;
location / {
expires $expires;
try_files $uri $uri/ /index.php?$query_string;
}
location /blog/ {
proxy_pass https://blog.example.com/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
location = /favicon.ico { access_log off; log_not_found off; }
location = /robots.txt { access_log off; log_not_found off; }
access_log off;
error_log /var/log/nginx/example.com-error.log error;
error_page 404 /index.php;
location ~ \.php$ {
fastcgi_split_path_info ^(.+\.php)(/.+)$;
fastcgi_pass unix:/var/run/php/php7.2-fpm.sock;
fastcgi_index index.php;
include fastcgi_params;
}
location ~ /\.(?!well-known).* {
deny all;
}
}
答案1
根据评论,这个改变解决了这个问题。
location ^~ /blog/ {
proxy_pass https://blog.example.com/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}