Nginx系列-4 proxy_pass使用和路径拼接问题

1.proxy_pass使用

proxy_pass指令用于请求的转发,请客户端请求转发至第三方服务器;如下所示:

复制代码
location /query {
	proxy_pass http://www.baidu.com;
}

上述案例将以/query开头的url请求转发至http://www.baidu.com.

proxy_pass用法较为简单,但使用时路径拼接问题需要重点关注,也是本章节的重点,以下通过案例的方案进行介绍和验证。
基准用例准备:

说明:路径拼接问题出现在前缀匹配上,完全匹配和正则表达式匹配不存在该问题。因此,可以借助完全匹配作为基准测试用例。

在8888端口上监听四个完全匹配路径:

shell 复制代码
server {
    server_name localhost;
    listen 8888;

     location = /test.html {
        return 200 "enter /test.html  ";
     }

    location = /proxy/test.html {
        return 200 "enter /proxy/test.html  ";
     }

     location = /ewen/test.html {
        return 200 "enter /ewen/test.html  ";
     }

     location = /ewentest.html {
        return 200 "enter /ewentest.html  ";
     }
}

测试结果如下所示:

shell 复制代码
[root@124 conf]# curl http://localhost:8888/test.html
enter /test.html  

[root@124 conf]# curl http://localhost:8888/proxy/test.html
enter /proxy/test.html 

[root@124 conf]# curl http://localhost:8888/ewen/test.html
enter /ewen/test.html  

[root@124 conf]# curl http://localhost:8888/ewentest.html
enter /ewentest.html  

问题来源:

shell 复制代码
location /代理url部分 {
	proxy_pass http://目标url部分
}

代理url部分是否以/结尾,以及目标url是否携带子路径和是否已/结尾等因素,可以将location /proxy {proxy_pass http://localhost:8888;}`组合形成8种场景:

shell 复制代码
#case1: 代理url部分不以/结尾,目标url没有子路径且不以/结尾
location /proxy {
	proxy_pass http://localhost:8888;
}
#case2: 代理url部分不以/结尾,目标没有子路径且url以/结尾
location /proxy {
	proxy_pass http://localhost:8888/;
}

#case3: 代理url部分以/结尾,目标url没有子路径且不以/结尾
location /proxy/ {
	proxy_pass http://localhost:8888;
}
#case4: 代理url部分以/结尾,目标url没有子路径,以/结尾
location /proxy/ {
	proxy_pass http://localhost:8888/;
}


#case5: 代理url不以/结尾,目标url存在子路径且不以/结尾
location /proxy {
	proxy_pass http://localhost:8888/ewen;
}
#case6: 代理url不以/结尾,目标url存在子路径且以/结尾
location /proxy {
	proxy_pass http://localhost:8888/ewen/;
}

#case7: 代理url以/结尾,目标url存在子路径且不以/结尾
location /proxy/ {
	proxy_pass http://localhost:8888/ewen;
}
#case8: 代理url以/结尾,目标url存在子路径且以/结尾
location /proxy/ {
	proxy_pass http://localhost:8888/ewen/;
}

当执行http://localhost:8001/proxy/test.html请求后,上述8种情况的访问路径为:

http://localhost:8888 http://localhost:8888/ http://localhost:8888/ewen http://localhost:8888/ewen/
/proxy/ http://localhost:8888/proxy/test.html http://localhost:8888/test.html http://localhost:8888/ewentest.html http://localhost:8888/ewen/test.html
/proxy http://localhost:8888/proxy/test.html http://localhost:8888/test.html http://localhost:8888/ewen/test.html http://localhost:8888/ewen//test.html

结论:

1 如果目标url仅包括ip和端口(没有斜线和子路径),如http://localhost:8888形式,则仅替换协议、域名和端口部分,其他路径保持不变:

如上述案例中:

shell 复制代码
location /proxy/ {
	proxy_pass http://localhost:8888;
}
和
location /proxy {
	proxy_pass http://localhost:8888;
}
场景下,访问http://localhost:8001/proxy/test.html
都会转发到http://localhost:8888/proxy/test.html

2 其他场景,客户端的请求的url路径删除协议-域名-端口后,进行代理url的剪切,将剪切后的部分直接拼接到目标url尾部,以下以案例进行过程说明。

访问http://localhost:8001/proxy/test.html时:

如果location定义为:

shell 复制代码
location /proxy {
	proxy_pass http://localhost:8888/ewen;
}

http://localhost:8001/proxy/test.html删除协议-域名-端口部分后,得到/proxy/test.html;

/proxy/test.html 删除代理url后,得到/test.html;

/test.html拼接至目标url即http://localhost:8888/ewen后,得到http://localhost:8888/ewen/test.html.

如果location定义为:

shell 复制代码
location /proxy/ {
	proxy_pass http://localhost:8888/ewen;
}

http://localhost:8001/proxy/test.html删除协议-域名-端口部分后,得到/proxy/test.html;

/proxy/test.html 删除代理url后,得到test.html;

test.html拼接至目标url即http://localhost:8888/ewen后,得到http://localhost:8888/ewentest.html.

相关推荐
qq_316411035 小时前
商用冷柜售后报修运维管理系统开发案例
运维
智码看视界5 小时前
Day59-阿里云ACK实战:生产级K8s集群部署与运维
运维·阿里云·kubernetes·k8s·日志监控·容器运维·阿里云ack
码视野7 小时前
基于 Vue3 + Element Plus 的【智慧新能源汽车充电桩运维调度与分时共享租赁系统】设计与实现(附完整源码与PRD)
运维·人工智能·汽车·vue3
qq_426003967 小时前
【UI自动化测试】UI自动化报错解决方案
运维·ui·自动化
网安蟹佬霸7 小时前
WAF绕过技术实战:从规则检测到编码绕过全指南(2026最新版,附Payload集与自动化脚本)
运维·安全·网络安全·架构·自动化·网安
小杨不想秃头7 小时前
信息安全工程师教程第二章密码学
运维·服务器·密码学
I'mChloe7 小时前
WGCLOUD怎么监控多台服务器?从Server、Agent 部署到监控面板实战
运维·服务器
Android系统攻城狮8 小时前
Linux PipeWire深度解析之pw_init调用流程与实战(八十三)
linux·运维·服务器·音频进阶·pipewire音频进阶
国科安芯8 小时前
轨道供电韧性:ASP4644四通道降压架构在低轨卫星平台电源管理中的适用性分析
运维·网络·数据库·嵌入式硬件·架构·状态模式·低轨卫星星座
Python自动化直播9 小时前
周末测试直播自动化时,发现一个棘手的并发问题
运维·自动化