代码之家  ›  专栏  ›  技术社区  ›  Martin Miguel Stevens

.htaccess头被Apache忽略

  •  3
  • Martin Miguel Stevens  · 技术社区  · 7 年前

    我有一个网站,使用相同的核心 .htaccess .htaccess 指令--提供一组基本的HTTP头:

        HTTP/1.1 200 OK
        Date: Mon, 12 Nov 2018 09:34:28 GMT
        Server: Apache
        Keep-Alive: timeout=5, max=100
        Connection: Keep-Alive
        Transfer-Encoding: chunked
        Content-Type: text/html; charset=UTF-8
    

    所以 .htaccess 正在阅读,对吗?

    是--htaccess文件包含HTTPS强制重定向和域名重定向(从.co.uk到.com地址(都到同一个网站帐户))

    PHP提供的标题也可以很好地加载

    测试页面上的PHP标题加载得很好:

    <?php
    header("Cache-Control: no-cache, must-revalidate");
    header('Content-Type: text/html; charset=utf-8');
    header("X-Clacks-Overhead: GNU Terry Pratchett");
    header("Content-Language: en");
    header("X-XSS-Protection: 1; mode=block");
    header("X-Frame-Options: SAMEORIGIN");
    header("X-Content-Type-Options: nosniff");
    ?>
    

    .htaccess 没有人知道。

    所以这是一个 语法错误!

    在那里的时候 是

    绝对地我完全同意。Apache错误日志为空!

    你试图做些什么来解决这个问题?

    • 证实 httpd.conf .htaccess
    • 注释掉并重新编写了各种规则,但没有任何效果
    • Server Fault -Stackoverflow帖子似乎没有关联,或者它们的问题有明显的差异。
    • 确认我的 具有正确的许可证(0644)

    在这里:

    Options +FollowSymLinks
    Options -Indexes
    RewriteEngine On
    ErrorDocument 404 /index.php?msg=404
    ErrorDocument 403 /index.php?msg=403
    
    #Set asset items to cache for 1 week.
    <FilesMatch "\.(gif|jpe?g|png|ico|css|js|swf|mp3)$">
         Header set Cache-Control "max-age=1972800, public, must-revalidate"
    </FilesMatch>
    
    RewriteCond %{HTTPS} !=on
    RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
    
    ## This does not appear to work (for either)
    #Header always set Strict-Transport-Security "max-age=31536000;" env=HTTPS
    Header always set Strict-Transport-Security "max-age=31536000; includeSubdomains;" "expr=%{HTTPS} == 'on'"
    Header set Expect-CT enforce,max-age=2592000
    
    RewriteCond %{HTTP_HOST} ^(www\.)?thewebsite\.co\.uk$ [NC]
    RewriteRule ^/?(.*)$ https://www.thewebsite.com%{REQUEST_URI} [R=301,L]
    
    ###
    ##### Seems to workdown to roughly this point.
    ###
    
    #force requests to begin with a slash.
    RewriteCond  %{REQUEST_URI}  !^$
    RewriteCond  %{REQUEST_URI}  !^/
    RewriteRule  .*              -    [R=403,L]
    
    RewriteCond %{HTTP_HOST} !^$
    RewriteCond %{HTTP_HOST} !^www\. [NC]
    RewriteRule ^ https://www.%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
    
    RewriteCond %{ENV:REDIRECT_STATUS} 200
    RewriteRule .* - [L]
    
    ### This file does not exist on the directory at present. 
    <Files .account-user.ini>
        order allow,deny
        deny from all
    </Files>
    
    ###
    #### None of these appear on assessment tools such as Security Headers 
    #### Or redbot.
    ###
    Header set Cache-Control no-cache,must-revalidate
    Header set X-Clacks-Overhead "GNU Terry Pratchett"
    Header set X-XSS-Protection 1;mode=block
    Header set X-Content-Type-Options nosniff
    Header always set X-Frame-Options SAMEORIGIN
    Header set Expect-CT enforce,max-age=2592000
    Header set Content-Language en
    Header set Referrer-Policy origin-when-cross-origin
        
    <LimitExcept GET POST HEAD>
        deny  from all
    </LimitExcept>
    

    • 似乎不起作用。
    • 全部的 该文件的部分内容在别处的其他实时站点上使用,没有问题。
    • 中的这些标头不会产生任何错误 .
    • 标题似乎以静默方式失败。
    • 没有记录Apache错误日志。
    • 这个 是 由于其他命令(如 mod_Rewrite (s) 被起诉

    从其他方(托管提供商)的研究来看,似乎 .htaccess 工作并加载所有正确的标题 对于非PHP页面

    即使是普通的PHP页面;标题为空。

    澄清

    • 无论什么.html页面都可以加载标题。
    • PHP页面显示由设置的标题 Header("...");
    • .htaccess . 这就是问题所在。

    看起来像 我的 .htaccess 无法为PHP页面设置标题。我怎样才能解决这个问题?

    3 回复  |  直到 6 年前
        1
  •  11
  •   digijay    7 年前

    当作为FastCGI模块工作时,PHP似乎忽略了.htaccess中定义的头文件。

    关于如何解决这个问题,有很多建议。在您的情况下,我建议使用一个定义所有标题的文件

    <?php
    // file headers.php
    header('Cache-Control: no-cache,must-revalidate');
    header('X-Clacks-Overhead: "GNU Terry Pratchett"');
    header('X-XSS-Protection: 1;mode=block');
    header('X-Content-Type-Options: nosniff');
    header('X-Frame-Options: SAMEORIGIN');
    header('Expect-CT: enforce,max-age=2592000');
    header('Content-Language: en');
    header('Referrer-Policy: origin-when-cross-origin');
    ?>
    

    并将其保存到DocumentRoot目录。然后将此条目添加到.htaccess文件中,以将其包含在每个请求中:

    php_value auto_prepend_file /var/www/html/headers.php     
    

    测试它:

    <?php
    // file test.php
    die("hello world");
    ?>
    

    并且正在发送标题:

    $ curl -I ubuntu-server.lan/test.php
    HTTP/1.1 200 OK
    Date: Sun, 25 Nov 2018 09:37:52 GMT
    Server: Apache/2.4.18 (Ubuntu)
    Cache-Control: no-cache,must-revalidate
    X-Clacks-Overhead: "GNU Terry Pratchett"
    X-XSS-Protection: 1;mode=block
    X-Content-Type-Options: nosniff
    X-Frame-Options: SAMEORIGIN
    Expect-CT: enforce,max-age=2592000
    Content-Language: en
    Referrer-Policy: origin-when-cross-origin
    Content-Type: text/html; charset=UTF-8
    

    希望这有帮助!


    先前的答复

    我认为这个问题是由httpd/apache2引起的 headers_module 未正确加载(尽管您在上述注释中另有说明)。您可以通过在终端中执行以下命令来检查:

    apachectl -M | grep headers_module
    

    headers_module (shared) (或类似),则必须激活httpd/apache2头文件模块。在CentOS系统上,您必须在配置中加载相应的源文件(默认) /etc/httpd/conf/httpd.conf ).

    你必须加上这一行

    LoadModule headers_module /usr/lib/apache2/modules/mod_headers.so
    

    sudo systemctl restart httpd.service

    使用EasyApache 4时,httpd/apache2模块所在的文件夹可能会有所不同,并且 /usr/lib64/apache2/modules/

    我希望这有帮助!

        2
  •  7
  •   covener    7 年前

    与其说它是FastCGI,不如说它是mod_proxy_fcgi,一种要求Apache通过将FastCGI传递给其他侦听器来“执行”FastCGI的方法。

    当您使用任何mod_proxy*模块时,.htaccess根本不会被处理,因为您充当了一个代理,并短路了任何与磁盘相关的配置部分。

        3
  •  0
  •   Martin Miguel Stevens    7 年前

    经过多次探索,发现问题出在PHP处理程序上 fastCGI (cgi)处理程序没有保留标题。

    suphp handler立即解决了问题。

        4
  •  0
  •   نرم افزار حضور و غیاب    5 年前

    我也有同样的问题。 请启用 cache Linux Ubuntu中的模块。

    sudo a2enmod cache
    

    sudo service apache2 start