{"id":62848,"date":"2025-04-29T12:14:34","date_gmt":"2025-04-29T04:14:34","guid":{"rendered":"https:\/\/fwq.ai\/blog\/62848\/"},"modified":"2025-04-29T12:14:34","modified_gmt":"2025-04-29T04:14:34","slug":"nginx%e5%a6%82%e4%bd%95%e5%ae%9e%e7%8e%b0%e5%9f%ba%e4%ba%8ecookie%e7%9a%84%e8%ae%bf%e9%97%ae%e6%8e%a7%e5%88%b6%e9%85%8d%e7%bd%ae-2","status":"publish","type":"post","link":"https:\/\/fwq.ai\/blog\/62848\/","title":{"rendered":"Nginx\u5982\u4f55\u5b9e\u73b0\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/img.php.cn\/upload\/article\/000\/887\/227\/169944277326868.jpg\" class=\"aligncenter\" title=\"Nginx\u5982\u4f55\u5b9e\u73b0\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e\u63d2\u56fe\" alt=\"Nginx\u5982\u4f55\u5b9e\u73b0\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e\u63d2\u56fe\" \/><\/p>\n<p>Nginx\u5982\u4f55\u5b9e\u73b0\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e\uff0c\u9700\u8981\u5177\u4f53\u4ee3\u7801\u793a\u4f8b<\/p>\n<p>\u5728Web\u5e94\u7528\u7a0b\u5e8f\u4e2d\uff0c\u8bbf\u95ee\u63a7\u5236\u662f\u4e00\u9879\u5173\u952e\u529f\u80fd\u3002\u901a\u8fc7\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e\uff0c\u53ef\u4ee5\u9650\u5236\u7528\u6237\u8bbf\u95ee\u7279\u5b9a\u7684\u9875\u9762\u6216\u8d44\u6e90\u3002\u672c\u6587\u5c06\u4ecb\u7ecd\u5982\u4f55\u4f7f\u7528Nginx\u6765\u5b9e\u73b0\u8fd9\u6837\u7684\u8bbf\u95ee\u63a7\u5236\uff0c\u5e76\u7ed9\u51fa\u5177\u4f53\u7684\u4ee3\u7801\u793a\u4f8b\u3002<\/p>\n<ol>\n<li>\u5f00\u542fNginx\u7684http_auth_request\u6a21\u5757<br \/>\u9996\u5148\uff0c\u9700\u8981\u786e\u4fddNginx\u5df2\u7ecf\u542f\u7528\u4e86http_auth_request\u6a21\u5757\u3002\u5982\u679c\u6ca1\u6709\u542f\u7528\uff0c\u53ef\u4ee5\u901a\u8fc7\u7f16\u8f91Nginx\u914d\u7f6e\u6587\u4ef6\u6dfb\u52a0\u8be5\u6a21\u5757\u3002<\/li>\n<\/ol>\n<pre>cd \/path\/to\/nginx\/source\/\n.\/configure --with-http_auth_request_module\nmake\nsudo make install<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<ol>\n<li>\u914d\u7f6eNginx\u7684\u8bbf\u95ee\u63a7\u5236\u89c4\u5219<br \/>\u5728Nginx\u914d\u7f6e\u6587\u4ef6\u4e2d\uff0c\u53ef\u4ee5\u901a\u8fc7location\u6307\u4ee4\u6765\u5b9a\u4e49\u8bbf\u95ee\u63a7\u5236\u89c4\u5219\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u6211\u4eec\u5c06\u8bbe\u7f6e\u53ea\u6709\u62e5\u6709\u7279\u5b9aCookie\u7684\u7528\u6237\u624d\u80fd\u8bbf\u95ee\u4e00\u4e2a\u53d7\u4fdd\u62a4\u7684\u9875\u9762\u3002<\/li>\n<\/ol>\n<pre>location \/protected {\n    auth_request \/auth;\n    error_page 401 = @error401;\n}\n\nlocation = \/auth {\n    internal;\n    proxy_pass http:\/\/backend\/auth;\n    proxy_pass_request_body off;\n    proxy_set_header Content-Length \"\";\n    proxy_set_header X-Original-URI $request_uri;\n}<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u4e0a\u8ff0\u914d\u7f6e\u4e2d\uff0clocation \/protected\u5b9a\u4e49\u4e86\u4e00\u4e2a\u53d7\u4fdd\u62a4\u7684\u9875\u9762\uff0cauth_request \/auth\u6307\u4ee4\u5c06\u4f1a\u53d1\u9001\u4e00\u4e2a\u8bf7\u6c42\u5230\/auth\u4f4d\u7f6e\u8fdb\u884c\u8ba4\u8bc1\u3002\u5982\u679c\u8ba4\u8bc1\u6210\u529f\uff0c\u5219\u5141\u8bb8\u8bbf\u95ee\u8be5\u9875\u9762\uff1b\u5426\u5219\uff0c\u5c06\u4f1a\u8fd4\u56de401\u9519\u8bef\u3002<\/p>\n<p>location = \/auth\u5b9a\u4e49\u4e86\u4e00\u4e2a\u5185\u90e8\u8bf7\u6c42\uff0c\u5b83\u5c06\u4f1a\u88ab\u4f20\u9012\u7ed9\u540e\u7aef\u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u6211\u4eec\u5047\u8bbe\u540e\u7aef\u670d\u52a1\u5668\u7684\u5730\u5740\u662fhttp:\/\/backend\uff0c\u8ba4\u8bc1\u63a5\u53e3\u4e3a\/auth\u3002\u901a\u8fc7proxy_pass\u6307\u4ee4\u5b9e\u73b0\u8bf7\u6c42\u7684\u8f6c\u53d1\uff0c\u5e76\u901a\u8fc7proxy_pass_request_body off\u548cproxy_set_header Content-Length &#8220;&#8221;\u7981\u7528\u8bf7\u6c42\u4f53\u7684\u4f20\u9012\u3002\u53e6\u5916\uff0c\u8fd8\u901a\u8fc7proxy_set_header X-Original-URI $request_uri\u4f20\u9012\u539f\u59cb\u7684URI\u4fe1\u606f\u7ed9\u540e\u7aef\u670d\u52a1\u5668\u3002<\/p>\n<ol>\n<li>\u7f16\u5199\u540e\u7aef\u670d\u52a1\u5668\u7684\u8ba4\u8bc1\u63a5\u53e3<br \/>\u5728\u4e0a\u4e00\u6b65\u7684\u914d\u7f6e\u4e2d\uff0c\u6211\u4eec\u5047\u8bbe\u540e\u7aef\u670d\u52a1\u5668\u7684\u5730\u5740\u4e3ahttp:\/\/backend\uff0c\u8ba4\u8bc1\u63a5\u53e3\u4e3a\/auth\u3002\u73b0\u5728\uff0c\u6211\u4eec\u6765\u7f16\u5199\u8be5\u63a5\u53e3\u7684\u5b9e\u9645\u5b9e\u73b0\u3002<\/li>\n<\/ol>\n<p>\u5b9e\u73b0\u4e00\u4e2a\u7b80\u5355\u7684\u8ba4\u8bc1\u63a5\u53e3\u53ef\u4ee5\u4f7f\u7528\u4efb\u4f55Web\u7f16\u7a0b\u8bed\u8a00\uff08\u5982Python\u3001PHP\u6216Java\uff09\u6765\u5b8c\u6210\u3002\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u4ee5Python\u4e3a\u4f8b\uff0c\u4f7f\u7528Flask\u6846\u67b6\u5b9e\u73b0\u4e00\u4e2a\u7b80\u5355\u7684\u63a5\u53e3\u3002<\/p>\n<pre>from flask import Flask, request\n\napp = Flask(__name__)\n\n@app.route('\/auth', methods=['POST'])\ndef auth():\n    cookie = request.headers.get('Cookie')\n    if cookie == 'your_cookie_value':\n        return 'OK'\n    else:\n        return 'Unauthorized', 401\n\nif __name__ == '__main__':\n    app.run()<\/pre>\n<p>  \u767b\u5f55\u540e\u590d\u5236   <\/p>\n<p>\u5728\u4e0a\u8ff0\u4ee3\u7801\u4e2d\uff0c\u6211\u4eec\u5b9a\u4e49\u4e86\u4e00\u4e2a\/auth\u7684\u8def\u7531\uff0c\u5b83\u63a5\u53d7POST\u8bf7\u6c42\u3002\u901a\u8fc7request.headers.get(&#8216;Cookie&#8217;)\u83b7\u53d6\u8bf7\u6c42\u4e2d\u7684Cookie\u4fe1\u606f\uff0c\u5e76\u4e0e\u9884\u8bbe\u7684Cookie\u8fdb\u884c\u6bd4\u8f83\u3002\u5982\u679c\u76f8\u7b26\uff0c\u5219\u8fd4\u56de&#8221;OK&#8221;\u8868\u793a\u8ba4\u8bc1\u6210\u529f\uff1b\u5426\u5219\uff0c\u8fd4\u56de401\u9519\u8bef\u8868\u793a\u8ba4\u8bc1\u5931\u8d25\u3002<\/p>\n<ol>\n<li>\u6d4b\u8bd5\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236<br \/>\u5b8c\u6210\u4ee5\u4e0a\u6b65\u9aa4\u540e\uff0c\u91cd\u542fNginx\u670d\u52a1\uff0c\u5e76\u8bbf\u95ee\u914d\u7f6e\u4e2d\u5b9a\u4e49\u7684\u53d7\u4fdd\u62a4\u9875\u9762\u3002\u53ea\u6709\u5728\u53d1\u9001\u5305\u542b\u6b63\u786eCookie\u7684\u8bf7\u6c42\u65f6\uff0c\u624d\u80fd\u591f\u6210\u529f\u8bbf\u95ee\u5230\u8be5\u9875\u9762\u3002<\/li>\n<\/ol>\n<p>\u7efc\u4e0a\u6240\u8ff0\uff0c\u6211\u4eec\u901a\u8fc7Nginx\u7684http_auth_request\u6a21\u5757\u3001\u8bbf\u95ee\u63a7\u5236\u89c4\u5219\u7684\u914d\u7f6e\u4ee5\u53ca\u540e\u7aef\u670d\u52a1\u5668\u7684\u8ba4\u8bc1\u63a5\u53e3\uff0c\u5b9e\u73b0\u4e86\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u3002\u8fd9\u6837\u7684\u914d\u7f6e\u53ef\u4ee5\u7075\u6d3b\u5730\u63a7\u5236\u7528\u6237\u5bf9\u7279\u5b9a\u9875\u9762\u6216\u8d44\u6e90\u7684\u8bbf\u95ee\u6743\u9650\u3002<\/p>\n<p>\u6ce8\u610f\uff1a\u5728\u5b9e\u9645\u751f\u4ea7\u73af\u5883\u4e2d\uff0c\u9700\u8981\u6839\u636e\u5b9e\u9645\u9700\u6c42\u548c\u5b89\u5168\u8981\u6c42\u8fdb\u884c\u66f4\u52a0\u4e25\u683c\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e\uff0c\u5e76\u5728\u540e\u7aef\u670d\u52a1\u5668\u7684\u8ba4\u8bc1\u63a5\u53e3\u4e2d\u5b9e\u73b0\u66f4\u52a0\u590d\u6742\u7684\u8ba4\u8bc1\u903b\u8f91\u3002\u4ee5\u4e0a\u793a\u4f8b\u4ec5\u63d0\u4f9b\u4e86\u57fa\u672c\u7684\u601d\u8def\u548c\u6f14\u793a\uff0c\u5177\u4f53\u7684\u5b9e\u73b0\u65b9\u5f0f\u9700\u8981\u6839\u636e\u5177\u4f53\u60c5\u51b5\u8fdb\u884c\u8c03\u6574\u3002<\/p>\n<p>\u4ee5\u4e0a\u5c31\u662fNginx\u5982\u4f55\u5b9e\u73b0\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e\u7684\u8be6\u7ec6\u5185\u5bb9\uff0c\u66f4\u591a\u8bf7\u5173\u6ce8FDCServers\u5176\u5b83\u76f8\u5173\u6587\u7ae0\uff01<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nginx\u5982\u4f55\u5b9e\u73b0\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e\uff0c\u9700\u8981\u5177\u4f53\u4ee3\u7801\u793a\u4f8b \u5728Web\u5e94\u7528\u7a0b\u5e8f\u4e2d\uff0c\u8bbf\u95ee\u63a7\u5236\u662f\u4e00\u9879\u5173\u952e\u529f\u80fd\u3002\u901a\u8fc7\u57fa\u4e8eCookie\u7684\u8bbf\u95ee\u63a7\u5236\u914d\u7f6e\uff0c\u53ef\u4ee5\u9650\u5236\u7528\u6237\u8bbf\u95ee\u7279\u5b9a\u7684\u9875\u9762\u6216\u8d44\u6e90\u3002\u672c\u6587\u5c06\u4ecb\u7ecd\u5982\u4f55\u4f7f\u7528Nginx\u6765\u5b9e\u73b0\u8fd9\u6837\u7684\u8bbf\u95ee\u63a7\u5236\uff0c\u5e76\u7ed9\u51fa\u5177\u4f53\u7684\u4ee3\u7801\u793a\u4f8b\u3002 \u5f00\u542fNginx\u7684http_auth_request\u6a21\u5757\u9996\u5148\uff0c\u9700\u8981\u786e\u4fddNginx\u5df2\u7ecf\u542f\u7528\u4e86http_auth_request\u6a21\u5757\u3002\u5982\u679c\u6ca1\u6709\u542f\u7528\uff0c\u53ef\u4ee5\u901a\u8fc7\u7f16\u8f91Nginx\u914d\u7f6e\u6587\u4ef6\u6dfb\u52a0\u8be5\u6a21\u5757\u3002 cd \/path\/to\/nginx\/source\/ .\/configure &#8211;with-http_auth_request_module make sudo make install \u767b\u5f55\u540e\u590d\u5236 \u914d\u7f6eNginx\u7684\u8bbf\u95ee\u63a7\u5236\u89c4\u5219\u5728Nginx\u914d\u7f6e\u6587\u4ef6\u4e2d\uff0c\u53ef\u4ee5\u901a\u8fc7location\u6307\u4ee4\u6765\u5b9a\u4e49\u8bbf\u95ee\u63a7\u5236\u89c4\u5219\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u6211\u4eec\u5c06\u8bbe\u7f6e\u53ea\u6709\u62e5\u6709\u7279\u5b9aCookie\u7684\u7528\u6237\u624d\u80fd\u8bbf\u95ee\u4e00\u4e2a\u53d7\u4fdd\u62a4\u7684\u9875\u9762\u3002 location \/protected { auth_request \/auth; error_page 401 = @error401; } location = \/auth { internal; proxy_pass http:\/\/backend\/auth; proxy_pass_request_body off; proxy_set_header Content-Length &#8220;&#8221;; proxy_set_header X-Original-URI $request_uri; } \u767b\u5f55\u540e\u590d\u5236 \u4e0a\u8ff0\u914d\u7f6e\u4e2d\uff0clocation \/protected\u5b9a\u4e49\u4e86\u4e00\u4e2a\u53d7\u4fdd\u62a4\u7684\u9875\u9762\uff0cauth_request \/auth\u6307\u4ee4\u5c06\u4f1a\u53d1\u9001\u4e00\u4e2a\u8bf7\u6c42\u5230\/auth\u4f4d\u7f6e\u8fdb\u884c\u8ba4\u8bc1\u3002\u5982\u679c\u8ba4\u8bc1\u6210\u529f\uff0c\u5219\u5141\u8bb8\u8bbf\u95ee\u8be5\u9875\u9762\uff1b\u5426\u5219\uff0c\u5c06\u4f1a\u8fd4\u56de401\u9519\u8bef\u3002 location = \/auth\u5b9a\u4e49\u4e86\u4e00\u4e2a\u5185\u90e8\u8bf7\u6c42\uff0c\u5b83\u5c06\u4f1a\u88ab\u4f20\u9012\u7ed9\u540e\u7aef\u670d\u52a1\u5668\u8fdb\u884c\u8ba4\u8bc1\u3002\u5728\u8fd9\u4e2a\u4f8b\u5b50\u4e2d\uff0c\u6211\u4eec\u5047\u8bbe\u540e\u7aef\u670d\u52a1\u5668\u7684\u5730\u5740\u662fhttp:\/\/backend\uff0c\u8ba4\u8bc1\u63a5\u53e3\u4e3a\/auth\u3002\u901a\u8fc7proxy_pass\u6307\u4ee4\u5b9e\u73b0\u8bf7\u6c42\u7684\u8f6c\u53d1\uff0c\u5e76\u901a\u8fc7proxy_pass_request_body off\u548cproxy_set_header Content-Length &#8220;&#8221;\u7981\u7528\u8bf7\u6c42\u4f53\u7684\u4f20\u9012\u3002\u53e6\u5916\uff0c\u8fd8\u901a\u8fc7proxy_set_header X-Original-URI $request_uri\u4f20\u9012\u539f\u59cb\u7684URI\u4fe1\u606f\u7ed9\u540e\u7aef\u670d\u52a1\u5668\u3002 \u7f16\u5199\u540e\u7aef\u670d\u52a1\u5668\u7684\u8ba4\u8bc1\u63a5\u53e3\u5728\u4e0a\u4e00\u6b65\u7684\u914d\u7f6e\u4e2d\uff0c\u6211\u4eec\u5047\u8bbe\u540e\u7aef\u670d\u52a1\u5668\u7684\u5730\u5740\u4e3ahttp:\/\/backend\uff0c\u8ba4\u8bc1\u63a5\u53e3\u4e3a\/auth\u3002\u73b0\u5728\uff0c\u6211\u4eec\u6765\u7f16\u5199\u8be5\u63a5\u53e3\u7684\u5b9e\u9645\u5b9e\u73b0\u3002 \u5b9e\u73b0\u4e00\u4e2a\u7b80\u5355\u7684\u8ba4\u8bc1\u63a5\u53e3\u53ef\u4ee5\u4f7f\u7528\u4efb\u4f55Web\u7f16\u7a0b\u8bed\u8a00\uff08\u5982Python\u3001PHP\u6216Java\uff09\u6765\u5b8c\u6210\u3002\u5728\u8fd9\u91cc\uff0c\u6211\u4eec\u4ee5Python\u4e3a\u4f8b\uff0c\u4f7f\u7528Flask\u6846\u67b6\u5b9e\u73b0\u4e00\u4e2a\u7b80\u5355\u7684\u63a5\u53e3\u3002 from flask [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-62848","post","type-post","status-publish","format-standard","hentry","category-os"],"_links":{"self":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts\/62848","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/comments?post=62848"}],"version-history":[{"count":0,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/posts\/62848\/revisions"}],"wp:attachment":[{"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/media?parent=62848"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/categories?post=62848"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fwq.ai\/blog\/wp-json\/wp\/v2\/tags?post=62848"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}