我有一个由JavaScript填充和提交的表单。表单由Laravel Form Builder构建。以下是表单的代码:
{!!Form::open(['url' => URL::to('billing/payments', array(), true ), 'id' => 'frmRebill'])!!}
{!!Form::hidden('plan', '', ['id' => 'plan'])!!}
{!!Form::hidden('annual', '', ['id' => 'annual'])!!}
{!!Form::close()!!}
如果从http://server.com/billing
访问表单并提交给https://server.com/billing/payment
或http://server.com/billing/payment
,则表明工作正常。
但是,当从https://server.com/billing
访问表单并将其提交给https://server.com/billing/payment
时,会出现403错误。
我正在使用Nginx。这是Nginx虚拟主机文件:
server {
listen 80;
server_name server.com
charset utf-8;
sendfile off;
client_max_body_size 10m;
index index.php;
error_log /var/log/nginx/error.log debug;
access_log /var/log/nginx/access.log;
root /var/www/server/public;
location /ping.html {
return 200 'pong';
}
location ~ ^/billing/(.+(?:css|js|woff|woff2|ttf))$ {
alias /var/www/billing/public/$1;
access_log off;
}
#billing code in laravel5
location /billing/ {
error_log /var/log/nginx/mkj-error.log debug;
alias /var/www/billing/public;
## Check for file existing and if there, stop ##
if (-f $request_filename) {
break;
}
## Check for file existing and if there, stop ##
if (-d $request_filename) {
break;
}
index index.php;
try_files $uri $uri/ @billing;
}
location @billing {
rewrite /billing/(.*)$ /billing/index.php?/$1 last;
}
location ~ \.php$ {
fastcgi_split_path_info ^(.+\.php)(/.+)$;
fastcgi_pass unix:/var/run/php5-fpm.sock;
fastcgi_index index.php;
set $php_root /var/www/s/public;
if ($request_uri ~ /billing) {
set $php_root /var/www/billing/public;
}
fastcgi_param PATH_TRANSLATED $php_root/index.php;
fastcgi_param SCRIPT_FILENAME $request_filename;
fastcgi_param REMOTE_ADDR $http_x_real_ip;
include fastcgi_params;
fastcgi_intercept_errors off;
fastcgi_buffer_size 16k;
fastcgi_buffers 4 16k;
fastcgi_read_timeout 120;
}
location / {
try_files $uri $uri/ /index.php?$query_string;
}
location ~ /\.ht {
deny all;
}
}
注意:csrf标记也是由表单生成的并保存在会话中。 有人可以弄清问题是什么,解决方案是什么?
答案 0 :(得分:0)
您需要配置HTTPS服务器。您的配置文件仅侦听http请求。
server {
listen 443 ssl;
server_name www.example.com;
ssl_certificate www.example.com.crt;
ssl_certificate_key www.example.com.key;
...
}
以下是有关如何http://nginx.org/en/docs/http/configuring_https_servers.html
的链接