点赞
评论
收藏
分享
举报
nginx 远端服务器访问控制模块
发表于2020-09-23 20:51

浏览 3.9k

文章标签

授权协议:
MIT license
原作者联系方式:
Wandenberg Peixoto <wandenberg@gmail.com>
功能说明:
nginx远端服务器访问控制模块。 可以通过配置远端服务器信息,实现对远端服务访问的控制。

Nginx Restrict Access Module

A module to restrict access to a server / location using the hostname of remote host, based on Nginx access module.

This module is not distributed with the Nginx source. See the installation instructions.

Configuration

An example:

pid         logs/nginx.pid;
error_log   logs/nginx-main_error.log debug;

# Development Mode
# master_process      off;
# daemon              off;
worker_processes    1;
worker_rlimit_core  500M;
working_directory /tmp;
debug_points abort;

events {
    worker_connections  1024;
    #use                 kqueue; # MacOS
    use                 epoll; # Linux
}

http {
    default_type    application/octet-stream;

    log_format main  '[$time_local] $host "$request" $request_time s '
                     '$status $body_bytes_sent "$http_referer" '
                     '"$http_user_agent" Remote: "$remote_addr" '
                     'remote_hostname: "$restrict_access_remote_hostname"';

    access_log      logs/nginx-http_access.log main;
    error_log       logs/nginx-http_error.log;

    restrict_access_address "$http_x_origin_ip";

    server {
        listen          8080;
        server_name     localhost;

        location / {
            allow_host "localhost" no_reverse_dns;
            allow_host "^p[0-9A-F]*\.dip0.t-ipconnect.de$";
            allow_host "^crawl-[0-9\-]*\.googlebot\.com$";
            allow_host "^.*\.ptr\.globo\.com$" no_reverse_dns;
            deny_host "all";
        }
    }
}

Variables

  • $restrict_access_remote_hostname - just list the hostname of remote host accessing the location

Directives

  • allow_host - name or a regular expression to match against the remote hostname, if it matches, the access is allowed. It accepts "all" as a special value and a "no_rever_dns" as second parameter to skip the reverse DNS check step.
  • deny_host - name or a regular expression to match against the remote hostname, if it matches, the access is denied. It accepts "all" as a special value and a "no_rever_dns" as second parameter to skip the reverse DNS check step.
  • restrict_access_address - could indicate a header or a variable with the IP to be checked as the origin. If it results in an empty value the client IP is used.

Installation instructions

Download Nginx Stable source and uncompress it (ex.: to ../nginx). You must then run ./configure with --add-module pointing to this project as usual. Something in the lines of:

$ ./configure \
    --add-module=../nginx-restrict-access-module \
    --prefix=/home/user/dev-workspace/nginx
$ make
$ make install

Running tests

This project uses nginx_test_helper on the test suite. So, after you've installed the module, you can just download the necessary gems:

$ cd test
$ bundle install

And run rspec pointing to where your Nginx binary is (default: /usr/local/nginx/sbin/nginx):

$ NGINX_EXEC=../path/to/my/nginx rspec .

Changelog

This is still a work in progress. Be the change. And take a look on the Changelog file.


已修改于2023-03-09 02:20
创作不易,留下一份鼓励
皮皮鲁

暂无个人介绍

关注



写下您的评论
发表评论
全部评论(0)

按点赞数排序

按时间排序

关于作者
皮皮鲁
这家伙很懒还未留下介绍~
85
文章
2
问答
45
粉丝
相关文章
概述 Nginx 从 1.9.0 开始加入了 stream 模块支持四层的代理,转发和负载均衡。但是,stream 模块的功能相对简单。对需要 ALG 处理的协议比如 FTP 的支持也远远不够。我试着去修改了 Nginx 的源代码,添加了alg模块。使之支持了 FTP主动模式和被动模式下的 ALG 功能。 Github 的源码地址为 : https://github.com/pei-jikui/nginx-alg。代码本身不困难,困难的是如何把代码模块化,有机地融入nginx原有的框架结构中,尽量少地修改已有的框架代码。而后者,需要对stream模块乃至nginx本身的框架和代码有一定的熟悉程度。图 1:FTP被动模式 数据连接 图2 :FTP主动模式 数据连接可能大家会说,Passive 模式不需要ALG 。准确
点赞 6
浏览 12.5k
使用配置方式:install./configure--add-module={module_dir}&&make&&makeinstallconfserver{ listen80; client_max_body_size100m; location/{ roothtml/upload; } #Uploadformshouldbesubmittedtothislocation location/upload{ #Passalteredrequestbodytothislocation upload_pass/example.php; #Storefilestothisdirectory #Thedirectoryishashed,subdirectories0123456789shouldexist
点赞 3
浏览 11.2k
使用方法:1.创建tableCREATETABLE oauth_access_token (id int(10)NOTNULLAUTO_INCREMENT,access_token varchar(255)DEFAULTNULL,expires_in int(10)NOTNULL,last_used_time int(10)NOTNULL,PRIMARYKEY(id),KEY ACCESS_TOKEN (access_token))ENGINE=InnoDBDEFAULTCHARSET=utf8;2.安装Oauth模块cd/work/nginx-1.8.0&&./configure--add-module=/work/nginx-http-oauth-module&&make3.添加配置请参照源码连接中的nginx.conf 4.使用Oauth模块a)创建访问tokenhttp://192.168.1.104/token?appid=
点赞 3
浏览 9.7k