在此特定设置中,如何防止nginx重定向到HTTPS?

如何解决在此特定设置中,如何防止nginx重定向到HTTPS?

我的设置有些混乱(没有选择),其中通过端口转发使本地计算机可用于Internet。它只能通过[public IP]:8000访问。我无法获得IP地址的“让我们加密”证书,但是可以从互联网访问的应用程序部分不需要加密。因此,我打算通过http://[public IP]:8000/的Internet和https://[local DNS name]/(端口80)的本地网络提供该应用程序。后者使用的证书由我们网络的根CA颁发。网络中的客户端信任此CA。

此外,从Internet访问时,页面的布局也会进行一些小的更改。这些更改是通过设置embedded查询参数进行的。

总而言之,我需要:

+--------------------------+--------------------------+----------+--------------------------------------+
|      Accessed using      |  Redirect to (ideally)   | URL args |            Current state             |
+--------------------------+--------------------------+----------+--------------------------------------+
| http://a.b.c.d:8000      | no redirect              | embedded | Arg not appended,redirects to HTTPS |
| http://localhost:8000    | no redirect              | embedded | Arg not appended,redirects to HTTPS |
| http://[local DNS name]  | https://[local DNS name] | no args  | Working as expected                  |
| https://[local DNS name] | no redirect              | no args  | Working as expected                  |
+--------------------------+--------------------------+----------+--------------------------------------+

对于前两行,我不想重定向到HTTPS,并且需要将?embedded附加到URL。

这是我的配置:

upstream channels-backend {
    server api:5000;
}

# Connections from the internet (no HTTPS)
server {
    listen 8000;
    listen [::]:8000;

    server_name [PUBLIC IP ADDRESS] localhost;

    keepalive_timeout 70;
    access_log /var/log/nginx/access.log;
    underscores_in_headers on;

    location = /favicon.ico {
        access_log off;
        log_not_found off;
    }

    location /admin/ {
        # Do not allow access to /admin/ from the internet.
        return 404;
    }

    location /static/rest_framework/ {
        alias /home/docker/backend/static/rest_framework/;
    }

    location /static/admin/ {
        alias /home/docker/backend/static/admin/;
    }

    location /files/media/ {
        alias /home/docker/backend/media/;
    }

    location /api/ {
        proxy_pass http://channels-backend/;
    }

    location ~* (service-worker\.js)$ {
        add_header 'Cache-Control' 'no-store,no-cache,must-revalidate,proxy-revalidate,max-age=0';
        expires off;
        proxy_no_cache 1;
    }

    location / {
        root /var/www/frontend/;
        # I want to add "?embedded" to the URL if accessed through http://[public IP]:8000.
        # I do not want to redirect to HTTPS.
        try_files $uri $uri/ /$uri.html?embedded =404;
    }
}

# Upgrade requests from local network to HTTPS
server {
    listen 80;

    keepalive_timeout 70;
    access_log /var/log/nginx/access.log;
    underscores_in_headers on;

    server_name [local DNS name] [local IP] localhost;

    # This works; it redirects to HTTPS.
    return 301 https://$http_host$request_uri;
}

# Server for connections from the local network (uses HTTPS)
server {
    listen 443 ssl;
    listen [::]:443 ssl;

    server_name [local DNS name] [local IP] localhost;

    ssl_password_file /etc/nginx/certificates/global.pass;
    ssl_session_cache shared:SSL:10m;
    ssl_session_timeout 10m;
    ssl_protocols TLSv1.2 TLSv1.1;
    ssl_certificate /etc/nginx/certificates/certificate.crt;
    ssl_certificate_key /etc/nginx/certificates/privatekey.key;

    keepalive_timeout 70;
    access_log /var/log/nginx/access.log;
    underscores_in_headers on;

    location = /favicon.ico {
        access_log off;
        log_not_found off;
    }

    location /admin/ {
        proxy_pass http://channels-backend/admin/;
    }

    location /static/rest_framework/ {
        alias /home/docker/backend/static/rest_framework/;
    }

    location /static/admin/ {
        alias /home/docker/backend/static/admin/;
    }

    location /files/media/ {
        alias /home/docker/backend/media/;
    }

    location /api/ {
        # Proxy to backend
        proxy_read_timeout 30;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Host $server_name;

        proxy_redirect off;

        proxy_pass http://channels-backend/;
    }

    # ignore cache frontend
    location ~* (service-worker\.js)$ {    
        add_header 'Cache-Control' 'no-store,max-age=0';    
        expires off;    
        proxy_no_cache 1;
    }

    location / {
        root /var/www/frontend/;
        # Do not add "?embedded" argument.
        try_files $uri $uri/ /$uri.html =404;
    }
}

如果需要的话,服务器既可以使用前端,也可以使用React和Django RF开发的API。它是使用Docker部署的。

任何指针将不胜感激。

编辑:我注释掉了除第一个服务器(端口8000)以外的所有内容,并且请求仍从https://localhost:8000重定向到http://localhost:8000。我不明白为什么。我正在使用隐身标签来排除缓存问题。

编辑2:我注意到Firefox设置了Upgrade-Insecure-Requests标头,初始请求为http://localhost:8000。如何忽略此标头并升级不安全的请求?此请求是由Firefox而不是前端应用程序发出的。

编辑3:请查看下面的配置,我现在使用该配置来找出问题所在。这怎么可能导致从HTTP重定向到HTTPS?现在只有一个服务器块,并且这里没有任何内容可以解释为希望从https://localhost:8000重定向到http://localhost:8000的愿望。重定向来自何处?请注意,我用重定向到Google,Yahoo和Facebook替换了某些部分。我没有重定向到任何这些。我立即升级到HTTPS,此配置完全不应该支持。值得一提的是,重定向以SSL_ERROR_RX_RECORD_TOO_LONG结尾。使用原始配置访问https://localhost/(端口80)时,证书被接受。

upstream channels-backend {
    server api:5000;
}

# Server for connections from the internet (does not use HTTPS)
server {
    listen 8000;
    listen [::]:8000 default_server;

    server_name localhost [public IP];

    keepalive_timeout 70;
    access_log /var/log/nginx/access.log;
    underscores_in_headers on;
    ssl off;

    location = /favicon.ico {
        access_log off;
        log_not_found off;
    }

    location /admin/ {
        # Do not allow access to /admin/ from the internet.
        return 404;
    }

    location /static/rest_framework/ {
        alias /home/docker/backend/static/rest_framework/;
    }

    location /static/admin/ {
        alias /home/docker/backend/static/admin/;
    }

    location /files/media/ {
        alias /home/docker/backend/media/;
    }

    location /api/ {
        proxy_pass http://channels-backend/;
    }

    location / {
        if ($args != "embedded") {
            return 301 https://google.com;
            # return 301 http://$http_host$request_uri?embedded;
        }

        return 301 https://yahoo.com;
        # root /var/www/frontend/;
        # try_files $uri $uri/ /$uri.html =404;
    }
}

解决方法

男孩,我觉得很蠢

在我的docker-compose.yml文件中,我不小心将端口8000映射到80:

  nginx-server:
    image: nginx-server
    build:
      context: ./
      dockerfile: .docker/dockerfiles/NginxDockerfile
    restart: on-failure
    ports:
      - "0.0.0.0:80:80"
      - "0.0.0.0:443:443"
      - "0.0.0.0:8000:80"  # Oops

因此,nginx会在端口8000上收到任何在端口8000上的请求。因此,即使是简单的配置,例如...

server {
    listen 8000;
    return 301 https://google.com;
}

...将导致尝试在端口80上升级到HTTPS(原因包括意外的重定向缓存,可能的默认行为等)。我感到非常困惑,但是修正了我的撰写说明可以解决问题:>

  nginx-server:
    image: nginx-server
    build:
      context: ./
      dockerfile: .docker/dockerfiles/NginxDockerfile
    restart: on-failure
    ports:
      - "0.0.0.0:80:80"
      - "0.0.0.0:443:443"
      - "0.0.0.0:8000:8000"  # Fixed

版权声明:本文内容由互联网用户自发贡献,该文观点与技术仅代表作者本人。本站仅提供信息存储空间服务,不拥有所有权,不承担相关法律责任。如发现本站有涉嫌侵权/违法违规的内容, 请发送邮件至 dio@foxmail.com 举报,一经查实,本站将立刻删除。

相关推荐


依赖报错 idea导入项目后依赖报错,解决方案:https://blog.csdn.net/weixin_42420249/article/details/81191861 依赖版本报错:更换其他版本 无法下载依赖可参考:https://blog.csdn.net/weixin_42628809/a
错误1:代码生成器依赖和mybatis依赖冲突 启动项目时报错如下 2021-12-03 13:33:33.927 ERROR 7228 [ main] o.s.b.d.LoggingFailureAnalysisReporter : *************************** APPL
错误1:gradle项目控制台输出为乱码 # 解决方案:https://blog.csdn.net/weixin_43501566/article/details/112482302 # 在gradle-wrapper.properties 添加以下内容 org.gradle.jvmargs=-Df
错误还原:在查询的过程中,传入的workType为0时,该条件不起作用 <select id="xxx"> SELECT di.id, di.name, di.work_type, di.updated... <where> <if test=&qu
报错如下,gcc版本太低 ^ server.c:5346:31: 错误:‘struct redisServer’没有名为‘server_cpulist’的成员 redisSetCpuAffinity(server.server_cpulist); ^ server.c: 在函数‘hasActiveC
解决方案1 1、改项目中.idea/workspace.xml配置文件,增加dynamic.classpath参数 2、搜索PropertiesComponent,添加如下 <property name="dynamic.classpath" value="tru
删除根组件app.vue中的默认代码后报错:Module Error (from ./node_modules/eslint-loader/index.js): 解决方案:关闭ESlint代码检测,在项目根目录创建vue.config.js,在文件中添加 module.exports = { lin
查看spark默认的python版本 [root@master day27]# pyspark /home/software/spark-2.3.4-bin-hadoop2.7/conf/spark-env.sh: line 2: /usr/local/hadoop/bin/hadoop: No s
使用本地python环境可以成功执行 import pandas as pd import matplotlib.pyplot as plt # 设置字体 plt.rcParams['font.sans-serif'] = ['SimHei'] # 能正确显示负号 p
错误1:Request method ‘DELETE‘ not supported 错误还原:controller层有一个接口,访问该接口时报错:Request method ‘DELETE‘ not supported 错误原因:没有接收到前端传入的参数,修改为如下 参考 错误2:cannot r
错误1:启动docker镜像时报错:Error response from daemon: driver failed programming external connectivity on endpoint quirky_allen 解决方法:重启docker -> systemctl r
错误1:private field ‘xxx‘ is never assigned 按Altʾnter快捷键,选择第2项 参考:https://blog.csdn.net/shi_hong_fei_hei/article/details/88814070 错误2:启动时报错,不能找到主启动类 #
报错如下,通过源不能下载,最后警告pip需升级版本 Requirement already satisfied: pip in c:\users\ychen\appdata\local\programs\python\python310\lib\site-packages (22.0.4) Coll
错误1:maven打包报错 错误还原:使用maven打包项目时报错如下 [ERROR] Failed to execute goal org.apache.maven.plugins:maven-resources-plugin:3.2.0:resources (default-resources)
错误1:服务调用时报错 服务消费者模块assess通过openFeign调用服务提供者模块hires 如下为服务提供者模块hires的控制层接口 @RestController @RequestMapping("/hires") public class FeignControl
错误1:运行项目后报如下错误 解决方案 报错2:Failed to execute goal org.apache.maven.plugins:maven-compiler-plugin:3.8.1:compile (default-compile) on project sb 解决方案:在pom.
参考 错误原因 过滤器或拦截器在生效时,redisTemplate还没有注入 解决方案:在注入容器时就生效 @Component //项目运行时就注入Spring容器 public class RedisBean { @Resource private RedisTemplate<String
使用vite构建项目报错 C:\Users\ychen\work>npm init @vitejs/app @vitejs/create-app is deprecated, use npm init vite instead C:\Users\ychen\AppData\Local\npm-