{"id":34045,"date":"2024-11-25T14:41:39","date_gmt":"2024-11-25T06:41:39","guid":{"rendered":"https:\/\/fwq.ai\/blog\/34045\/"},"modified":"2024-11-25T14:41:39","modified_gmt":"2024-11-25T06:41:39","slug":"%e6%80%bb%e7%bb%93%e5%85%b3%e4%ba%8ereferer%e4%b8%a2%e5%a4%b1%e7%9a%84%e9%97%ae%e9%a2%98%ef%bc%88%e5%be%ae%e4%bf%a1h5%e6%94%af%e4%bb%98%ef%bc%89","status":"publish","type":"post","link":"https:\/\/fwq.ai\/blog\/34045\/","title":{"rendered":"\u603b\u7ed3\u5173\u4e8eReferer\u4e22\u5931\u7684\u95ee\u9898\uff08\u5fae\u4fe1H5\u652f\u4ed8\uff09"},"content":{"rendered":"<p><em><\/em> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<\/p>\n<p>\u6700\u8fd1\u516c\u53f8\u7533\u8bf7\u4e86\u5fae\u4fe1\u7684h5\u652f\u4ed8 \u76f8\u5173\u652f\u4ed8\u6587\u6863\u89c1\u8fd9\u91cc https:\/\/pay.weixin.qq.com\/wiki\/doc\/api\/h5.php?chapter=15_4\u53d1\u5e03\u4e0a\u7ebf\u540e\u53d1\u8d77\u652f\u4ed8 \u4e00\u76f4\u62a5\u9519 \u5546\u5bb6\u53c2\u6570\u683c\u5f0f\u6709\u8bef\uff0c\u8bf7\u8054\u7cfb\u5546\u5bb6\u89e3\u51b3 \u6839\u636e\u5fae\u4fe1\u5b98\u65b9\u6587\u6863\u7684\u9519\u8bef\u63d0\u793a \u5e94\u8be5\u662f referer \u4e22\u5931\u7684\u95ee\u9898 \u4e8e\u662f\u5b9a\u4f4d\u4e00\u901a\u53d1\u73b0\u8fd8\u771f\u662f referer \u4e22\u5931\u4e86 \u8bb0\u5f55\u4e0b\u89e3\u51b3\u95ee\u9898\u8fc7\u7a0b\u3002<\/p>\n<h3> <span><\/span>Referer \u662f\u4ec0\u4e48<\/h3>\n<p>HTTP Referer\u662f HTTP \u8bf7\u6c42 header \u5934\u4fe1\u606f\u7684\u4e00\u90e8\u5206 \u5f53\u6d4f\u89c8\u5668\u5411web\u670d\u52a1\u5668\u53d1\u9001\u8bf7\u6c42\u7684\u65f6\u5019\uff0c\u4e00\u822c\u4f1a\u5e26\u4e0aReferer<\/p>\n<p>\u544a\u8bc9\u670d\u52a1\u5668\u6211\u662f\u4ece\u54ea\u4e2a\u9875\u9762\u94fe\u63a5\u8fc7\u6765\u7684\uff0c\u670d\u52a1\u5668\u85c9\u6b64\u53ef\u4ee5\u83b7\u5f97\u4e00\u4e9b\u4fe1\u606f\u7528\u4e8e\u5904\u7406\u3002<\/p>\n<p>\u6bd4\u5982\u6211\u4eec\u5728 Chrome \u6d4f\u89c8\u5668\u7684\u63a7\u5236\u53f0\u4e0b \u53ef\u4ee5\u770b\u5230 Request Headers \u4e0b\u6709\u7c7b\u4f3c\u5982\u4e0b\u7684\u4fe1\u606f<\/p>\n<pre>Provisional&nbsp;headers&nbsp;are&nbsp;shown\nAccept:&nbsp;\n\/\nOrigin:&nbsp;local.test5.show\nReferer:&nbsp;local.test5.show\/test\/show\nUser-Agent:&nbsp;Mozilla\/5.0&nbsp;(Windows&nbsp;NT&nbsp;10.0;&nbsp;Win64;&nbsp;x64)&nbsp;AppleWebKit\/537.36&nbsp;(KHTML,&nbsp;like&nbsp;Gecko)&nbsp;Chrome\/70.0.3538.77&nbsp;Safari\/537.36<\/pre>\n<p> \u767b\u5f55\u540e\u590d\u5236 <\/p>\n<p>\u5176\u4e2d Referer \u5c31\u662f\u8be5\u5c5e\u6027\u4e86<\/p>\n<p><strong>Referer<\/strong> \u7684\u6b63\u786e\u82f1\u8bed\u62fc\u6cd5\u662f <strong>referrer<\/strong>\u3002\u7531\u4e8e\u65e9\u671f HTTP \u89c4\u8303\u7684\u62fc\u5199\u9519\u8bef\uff0c\u4e3a\u4e86\u4fdd\u6301\u5411\u540e\u517c\u5bb9\u5c31\u5c06\u9519\u5c31\u9519\u4e86<\/p>\n<h3> <span><\/span>Referer \u7684\u4f5c\u7528<\/h3>\n<h4> <span><\/span>\u9632\u76d7\u94fe<\/h4>\n<p>\u6bd4\u5982\u4f60\u53d1\u73b0\u8bbf\u95ee\u52a0\u8f7d\u81ea\u5df1\u7684\u8d44\u6e90 \u800c referer\u4e0d\u662f\u81ea\u5df1\u7684\u7ad9\u70b9 \u5c31\u53ef\u4ee5\u5c4f\u853d\u5b83<\/p>\n<h4> <span><\/span>\u9632\u6b62\u6076\u610f\u8bf7\u6c42<\/h4>\n<p>\u8fd9\u70b9\u540c\u4e0a<\/p>\n<h4> <span><\/span>\u9ad8\u7ea7\u7528\u6cd5<\/h4>\n<p>\u6bd4\u5982\u5fae\u4fe1H5\u652f\u4ed8 \u4e5f\u9700\u8981\u8fd9\u4e2a \u5c31\u4e0d\u77e5\u9053\u4ed6\u4eec\u505a\u5565\u7528\u4e86(hhh<\/p>\n<h3> <span><\/span>Referer \u4e22\u5931<\/h3>\n<p>\u5173\u4e8e Referer \u4e22\u5931\u7684\u95ee\u9898 \u9996\u5148 referer \u662f\u7531\u5ba2\u6237\u7aef\u7684\u6d4f\u89c8\u5668\u53d1\u9001\u5230\u670d\u52a1\u5668\u4e0a\uff0c\u4e14\u5728\u5ba2\u6237\u7aef\u53ef\u4ee5\u901a\u8fc7 document.referrer \u6765\u83b7\u53d6\uff0c\u4e5f\u5c31\u662f\u8bf4referer\u7684\u53d1\u9001\u5b9e\u9645\u4e0a\u662f\u4e00\u4e2a\u6d4f\u89c8\u5668\u884c\u4e3a\uff0c\u53d1\u9001\u4e0e\u5426\u7684\u51b3\u5b9a\u6743\u662f\u5728\u6d4f\u89c8\u5668\u624b\u91cc\u3002\u867d\u7136\u8fd9\u6837\u8bf4\uff0c\u4f46\u662fHTTP\u534f\u8bae\u5bf9\u4ec0\u4e48\u60c5\u51b5\u4e0b\uff0c\u6d4f\u89c8\u5668\u8be5\u53d1\u9001\uff0c\u4ec0\u4e48\u60c5\u51b5\u4e0b\u4e0d\u8be5\u53d1\u9001\u6709\u7740\u4e25\u683c\u7684\u89c4\u5b9a\u3002<\/p>\n<h4> <span><\/span>\u603b\u7ed3\u4e0b Referer \u4e22\u5931\u7684\u51e0\u79cd\u60c5\u51b5<\/h4>\n<p>1.\u5f53\u7f51\u7ad9\u4f7f\u7528refresh\u5b57\u6bb5\u8fdb\u884c\u8df3\u8f6c\u7684\u65f6\u5019\uff0c\u5927\u591a\u6570\u6d4f\u89c8\u5668\u4e0d\u53d1\u9001referer<\/p>\n<p>2.\u4ece\u7528\u6237\u4ece\u4e00\u4e2aHTTPS\u7684\u7f51\u7ad9\u70b9\u51fb\u94fe\u63a5\u5230\u53e6\u4e00\u4e2aHTTP\u7684\u7f51\u7ad9\u65f6\uff0c\u4e0d\u53d1\u9001referer<\/p>\n<p>3.html5\u4e2d\uff0ca\u6807\u7b7e\u7684rel = \u201cnoreferrer\u201d, \u53ef\u4ee5\u8ba9\u6d4f\u89c8\u5668\u4e0d\u53d1\u9001referer<\/p>\n<p>4.\u4f7f\u7528Data URI scheme\u94fe\u63a5\u7684\uff0c\u6d4f\u89c8\u5668\u4e5f\u4e0d\u53d1\u9001referer<\/p>\n<p>5.\u4f7f\u7528Content Security Policy, \u4e5f\u53ef\u4ee5\u8ba9\u6d4f\u89c8\u5668\u4e0d\u53d1\u9001referer<\/p>\n<p>6.\u5728html\u5934\u90e8\u4e2d\u4f7f\u7528meta\u6807\u7b7e\u6765\u63a7\u5236\u4e0d\u8ba9\u6d4f\u89c8\u5668\u53d1\u9001referer<\/p>\n<h3> <span><\/span>\u81ea\u52a8\u751f\u6210URL\u94fe\u63a5HTTPS\u53d8HTTP<\/h3>\n<p>\u6709\u65f6\u5019\u9700\u8981\u5728API\u9879\u76ee\u4e2d\u751f\u6210\u4e00\u4e9bURL\u94fe\u63a5\u8fd4\u56de \u4f46\u662f\u670d\u52a1\u5668\u7aef\u5df2\u7ecf\u914d\u7f6e\u4e86\u652f\u6301HTTPS\uff0c\u901a\u8fc7HTTPS\u8bbf\u95ee\u7684\u65f6\u5019\u751f\u6210\u7684URL\u4ecd\u7136\u662fHTTP<\/p>\n<p>\u5173\u4e8e\u8fd9\u4e2a\u95ee\u9898\u5176\u5b9e\u662f\u670d\u52a1\u5668 <strong>\u914d\u7f6e<\/strong> \u95ee\u9898 \u548c \u4e0b\u9762\u7c7b\u4f3c<\/p>\n<p>\u56de\u5230\u6211\u9047\u5230\u7684\u5fae\u4fe1\u652f\u4ed8\u95ee\u9898 \u8ddf\u8e2a\u4e86\u4e00\u5708\u6d4f\u89c8\u5668\u7684\u8df3\u8f6c\u4e4b\u540e\u53d1\u73b0\u662f\u5c5e\u6027\u7b2c\u4e8c\u79cd\u60c5\u51b5 \u4ece HTTPS \u7ad9\u70b9\u8df3\u5230 HTTP \u7ad9\u70b9 \u4e22\u5931\u4e86 Referer\u3010ps:\u53cd\u8fc7\u6765\u4eceHTTP\u5230HTTPS\u662f\u6ca1\u95ee\u9898\u7684 \u4e0d\u4f1a\u4e22\u5931 Referer\u3011 \u4e2d\u95f4\u85cf\u7684\u6bd4\u8f83\u6df1<\/p>\n<p>\u5f53\u7136\u6211\u4e00\u5f00\u59cb\u6ca1\u6709\u53d1\u73b0\u8fd9\u4e2a\u95ee\u9898 \u56e0\u4e3a\u4ece\u524d\u7aef\u8bf7\u6c42\u5230 API \u6574\u4e2a\u90fd\u6ca1\u6709\u95ee\u9898 \u5168\u90e8\u9879\u76ee\u5df2\u7ecf\u5168\u7ebf\u90e8\u7f72\u4e86 HTTPS , Referer \u4fe1\u606f\u4e5f\u6709\u643a\u5e26 \u7136\u540e\u5230\u6700\u540e\u4e00\u6b65\u5fae\u4fe1\u7684\u652f\u4ed8\u8bf7\u6c42URL\u7684\u65f6\u5019 Referer \u5c31\u4e22\u5931\u4e86.<\/p>\n<p>\u540e\u9762\u53d1\u73b0\u5728\u8bf7\u6c42\u5230API\u9879\u76ee\u7684\u65f6\u5019 API\u9879\u76ee\u8fd4\u56de\u4e86\u4e00\u4e2a URL \u7ed9\u524d\u7aef \u8fd9\u4e2a URL \u662f\u540e\u7aef\u4ee3\u7801\u6839\u636e\u89c4\u5219\u751f\u6210\u7684(Laravel \u91cc\u7684 action \u8f85\u52a9\u51fd\u6570) \u8fd9\u4e2a\u51fd\u6570\u672c\u8eab\u5e76\u6ca1\u6709\u4ec0\u4e48\u95ee\u9898 \u4f46\u662f\u751f\u6210\u7684URL\u94fe\u63a5 \u662f HTTP \u4e86 \u53c8\u641e\u4e8b\u60c5\uff01\uff01\uff01<\/p>\n<p>API\u9879\u76ee\u914d\u7f6e\u7684\u662f HTTPS \u8bf7\u6c42 \u4f46\u662f\u751f\u6210\u7684URL\u662f HTTP \u95ee\u9898\u5c31\u662f\u8fd9\u91cc\u4e86 \u8bf7\u6c42\u8fd0\u7ef4\u54e5\u534f\u52a9 \u6700\u540e\u53d1\u73b0\u662f Nginx \u53cd\u5411\u4ee3\u7406\u4e2d\u914d\u7f6e\u7684\u95ee\u9898<\/p>\n<p>nginx\u670d\u52a1\u5668\u914d\u7f6e\u7247\u6bb5\u5982\u4e0b\uff1a<\/p>\n<pre>location \/ {\n    proxy_pass http:\/\/114.114.114.114:80;\n  }<\/pre>\n<p> \u767b\u5f55\u540e\u590d\u5236 <\/p>\n<p>\u53ef\u4ee5\u770b\u5230 proxy_pass \u53c2\u6570 \u6307\u5411\u7684\u662f HTTP\u7684\u534f\u8bae \u6240\u4ee5\u5728 \u540e\u53f0\u83b7\u53d6\u7684 URL \u90fd\u662fHTTP\u534f\u8bae\u7684<\/p>\n<p>\u628a\u4ee3\u7406\u8fd9\u8bbe\u7f6e\u6210 https:\/\/114.114.114.114:443; \u5373\u53ef \u95ee\u9898\u7ec8\u89e3\u51b3<\/p>\n<p><span>&nbsp;\u63a8\u8350\uff1a\u300a\u300b<\/span>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;<\/p>\n<p style=\"margin: 35px 0px\"><em><\/em><\/p>\n<p>\u4ee5\u4e0a\u5c31\u662f\u603b\u7ed3\u5173\u4e8eReferer\u4e22\u5931\u7684\u95ee\u9898\uff08\u5fae\u4fe1H5\u652f\u4ed8\uff09\u7684\u8be6\u7ec6\u5185\u5bb9\uff0c\u66f4\u591a\u8bf7\u5173\u6ce8\u7c73\u4e91\u5176\u5b83\u76f8\u5173\u6587\u7ae0\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; \u6700\u8fd1\u516c\u53f8\u7533\u8bf7\u4e86\u5fae\u4fe1\u7684h5\u652f\u4ed8 \u76f8\u5173\u652f\u4ed8\u6587\u6863\u89c1\u8fd9\u91cc https:\/\/pay.weixin.qq.com\/wiki\/doc\/api\/h5.php?chapter=15_4\u53d1\u5e03\u4e0a\u7ebf\u540e\u53d1\u8d77\u652f\u4ed8 \u4e00\u76f4\u62a5\u9519 \u5546\u5bb6\u53c2\u6570\u683c\u5f0f\u6709\u8bef\uff0c\u8bf7\u8054\u7cfb\u5546\u5bb6\u89e3\u51b3 \u6839\u636e\u5fae\u4fe1\u5b98\u65b9\u6587\u6863\u7684\u9519\u8bef\u63d0\u793a \u5e94\u8be5\u662f referer \u4e22\u5931\u7684\u95ee\u9898 \u4e8e\u662f\u5b9a\u4f4d\u4e00\u901a\u53d1\u73b0\u8fd8\u771f\u662f referer \u4e22\u5931\u4e86 \u8bb0\u5f55\u4e0b\u89e3\u51b3\u95ee\u9898\u8fc7\u7a0b\u3002 Referer \u662f\u4ec0\u4e48 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[],"class_list":["post-34045","post","type-post","status-publish","format-standard","hentry","category-19"],"_links":{"self":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts\/34045","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/comments?post=34045"}],"version-history":[{"count":0,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts\/34045\/revisions"}],"wp:attachment":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/media?parent=34045"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/categories?post=34045"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/tags?post=34045"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}