CMSPRO安装有2中方式,第一种方式使用程序包安装(VPS或服务器),第二种是傻瓜式的在线安装(虚拟空间或免费空间);
下面详细讲解下伪静态设置与区分;
使用程序包安装
程序安装包最优,而且最安全,不会暴漏系统框架;唯一需要的是需要设置运行目录(见教程:https://www.cmspro.cn/help/2)
使用程序包的伪静态,直接参考教程,打开程序目录下的 Rewrite 文件夹,将对应的伪静态信息填写到伪静态配置中;
使用在线安装
在线安装时为了兼容虚拟空间以及根目录下运行CMSPRO而生,没有使用程序包安装设置运行目录安全,但是为了能正常使用也做了相对的安全措施;
在线安装只需将在线安装文件setup.php放到主机的根目录,即可执行在线安装;伪静态信息也相应的做了差异化的调整;
下面是根据不同Web环境的伪静态信息,Apache的Web环境系统会自动创建伪静态到根目录,常规下会自动加载伪静态,无需设置;
-
Apache伪静态
.htaccess<IfModule mod_rewrite.c> RewriteEngine On # 保留 Authorization 头(部分 Apache + CGI 组合会丢弃) RewriteCond %{HTTP:Authorization} . RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] # -------------------------- # 禁止访问隐藏文件(允许 .well-known) # -------------------------- RewriteRule (^|/)\.well-known - [L] RewriteRule (^|/)\. - [F,L] # -------------------------- # 上传目录禁止执行 PHP(FilesMatch 只匹配文件名不含路径,故必须用 RewriteRule) # -------------------------- RewriteRule ^(public/)?[Uu]ploads/.*\.php$ - [F,L] # -------------------------- # 静态资源映射到 public/(运行目录为项目根,资源实际存放于 public/ 下) # -------------------------- # 真实文件直接输出:运行目录已是 public/(其下无 public 子目录), # 或显式请求 /public/ 下的文件。项目根的 .env、vendor/、composer.json 不在放行范围。 RewriteCond %{DOCUMENT_ROOT}/public !-d [OR] RewriteCond %{REQUEST_URI} /public/.+ RewriteCond %{REQUEST_FILENAME} -f RewriteRule ^ - [L] # 资源请求映射到 public/。必须带 -f 条件:文件不存在时不打标记, # 落到下面的前端控制器由 PHP 兜底 404;排除 .php 以防执行非预期脚本。 RewriteCond %{DOCUMENT_ROOT}/public/$1 -f RewriteCond $1 !\.php$ RewriteRule ^(.+)$ public/$1 [E=CMSPRO_ASSET:1,L] # -------------------------- # Laravel URL 重写(所有其余请求转发到 index.php) # -------------------------- # 用标记而非 !-f 限定:项目根下 composer.json、config/ 都是真实文件, # 用 !-f 会被 Apache 直接输出造成信息泄露。 RewriteCond %{ENV:CMSPRO_ASSET} !=1 RewriteRule ^ index.php [L,QSA] </IfModule> # -------------------------- # 静态资源长期缓存(30 天)。ExpiresDefault 已输出等效 Cache-Control,无需 mod_headers; # 必须用 IfModule 包裹:模块未加载时裸写指令会导致整站 500 # -------------------------- <IfModule mod_expires.c> <FilesMatch "\.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$"> ExpiresActive On ExpiresDefault "access plus 30 days" </FilesMatch> </IfModule> -
NGINX伪静态
# CmsPro Nginx 伪静态配置(运行目录为项目根) # 将以下内容添加到站点 server 块中 # 核心:Laravel URL 重写规则(与 public 场景相比仅此处不同:候选路径加 /public 前缀) location / { try_files /public$uri /index.php?$query_string; } # 禁止访问隐藏文件(.env、.git 等),允许 .well-known location ~ /\.(?!well-known).* { deny all; } # 上传目录禁止执行 PHP(安全加固) location ~* ^/Uploads/.*\.php$ { deny all; } # 静态资源长期缓存(30 天) # 根目录运行时本 location 优先于 location / 命中,必须同样映射到 public/ 才能找到资源 location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$ { expires 30d; add_header Cache-Control "public, immutable"; access_log off; try_files /public$uri =404; } -
IIS伪静态
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <rewrite> <rules> <!-- 上传目录禁止执行 PHP --> <rule name="CmsPro uploads PHP deny" stopProcessing="true"> <match url="^(public/)?uploads/.*\.php$" ignoreCase="true" /> <action type="CustomResponse" statusCode="403" statusReason="Forbidden" statusDescription="Forbidden" /> </rule> <!-- 显式请求 /public/ 下的真实文件(安装入口等)时直接交给 IIS --> <rule name="CmsPro public files" stopProcessing="true"> <match url="^public/(.+)$" /> <conditions> <add input="{REQUEST_FILENAME}" matchType="IsFile" /> </conditions> <action type="None" /> </rule> <!-- 根目录资源 URL 映射到 public\ 下;PHP 文件不作为静态资源映射 --> <rule name="CmsPro public assets" stopProcessing="true"> <match url="^(.+)$" /> <conditions logicalGrouping="MatchAll"> <add input="{APPL_PHYSICAL_PATH}public\{R:1}" matchType="IsFile" /> <add input="{R:1}" pattern="\.php$" negate="true" /> </conditions> <action type="Rewrite" url="public/{R:1}" appendQueryString="true" /> </rule> <!-- Laravel URL 重写(其余请求转发到 index.php,与 public 场景相比仅少了 IsFile/IsDirectory 条件) --> <rule name="Laravel to index.php" stopProcessing="true"> <match url="^(.*)$" /> <action type="Rewrite" url="index.php" appendQueryString="true" /> </rule> </rules> </rewrite> <!-- 禁止访问隐藏文件 --> <security> <requestFiltering> <hiddenSegments applyToWebDAV="false"> <add segment=".env" /> <add segment=".git" /> <add segment=".svn" /> </hiddenSegments> </requestFiltering> </security> <!-- 上传目录禁止执行 PHP --> <location path="Uploads"> <system.webServer> <handlers> <remove name="PHP_via_FastCGI" /> <remove name="PHP7_via_FastCGI" /> <remove name="PHP8_via_FastCGI" /> </handlers> </system.webServer> </location> <!-- 静态资源缓存(30 天) --> <staticContent> <clientCache cacheControlMode="UseMaxAge" cacheControlMaxAge="30.00:00:00" cacheControlCustom="public, immutable" /> </staticContent> </system.webServer> </configuration>