CMSPRO社区

CMSPRO伪静态设置教程 回复

CMSPRO安装有2中方式,第一种方式使用程序包安装(VPS或服务器),第二种是傻瓜式的在线安装(虚拟空间或免费空间);

下面详细讲解下伪静态设置与区分;

使用程序包安装

程序安装包最优,而且最安全,不会暴漏系统框架;唯一需要的是需要设置运行目录(见教程:https://www.cmspro.cn/help/2)

使用程序包的伪静态,直接参考教程,打开程序目录下的 Rewrite 文件夹,将对应的伪静态信息填写到伪静态配置中;

使用在线安装

在线安装时为了兼容虚拟空间以及根目录下运行CMSPRO而生,没有使用程序包安装设置运行目录安全,但是为了能正常使用也做了相对的安全措施;

在线安装只需将在线安装文件setup.php放到主机的根目录,即可执行在线安装;伪静态信息也相应的做了差异化的调整;

下面是根据不同Web环境的伪静态信息,Apache的Web环境系统会自动创建伪静态到根目录,常规下会自动加载伪静态,无需设置;

  • Apache伪静态 .htaccess

    <IfModule mod_rewrite.c>
        RewriteEngine On
    
        # 保留 Authorization 头(部分 Apache + CGI 组合会丢弃)
        RewriteCond %{HTTP:Authorization} .
        RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
    
        # --------------------------
        # 禁止访问隐藏文件(允许 .well-known)
        # --------------------------
        RewriteRule (^|/)\.well-known - [L]
        RewriteRule (^|/)\. - [F,L]
    
        # --------------------------
        # 上传目录禁止执行 PHP(FilesMatch 只匹配文件名不含路径,故必须用 RewriteRule)
        # --------------------------
        RewriteRule ^(public/)?[Uu]ploads/.*\.php$ - [F,L]
    
        # --------------------------
        # 静态资源映射到 public/(运行目录为项目根,资源实际存放于 public/ 下)
        # --------------------------
        # 真实文件直接输出:运行目录已是 public/(其下无 public 子目录),
        # 或显式请求 /public/ 下的文件。项目根的 .env、vendor/、composer.json 不在放行范围。
        RewriteCond %{DOCUMENT_ROOT}/public !-d [OR]
        RewriteCond %{REQUEST_URI} /public/.+
        RewriteCond %{REQUEST_FILENAME} -f
        RewriteRule ^ - [L]
    
        # 资源请求映射到 public/。必须带 -f 条件:文件不存在时不打标记,
        # 落到下面的前端控制器由 PHP 兜底 404;排除 .php 以防执行非预期脚本。
        RewriteCond %{DOCUMENT_ROOT}/public/$1 -f
        RewriteCond $1 !\.php$
        RewriteRule ^(.+)$ public/$1 [E=CMSPRO_ASSET:1,L]
    
        # --------------------------
        # Laravel URL 重写(所有其余请求转发到 index.php)
        # --------------------------
        # 用标记而非 !-f 限定:项目根下 composer.json、config/ 都是真实文件,
        # 用 !-f 会被 Apache 直接输出造成信息泄露。
        RewriteCond %{ENV:CMSPRO_ASSET} !=1
        RewriteRule ^ index.php [L,QSA]
    </IfModule>
    
    # --------------------------
    # 静态资源长期缓存(30 天)。ExpiresDefault 已输出等效 Cache-Control,无需 mod_headers;
    # 必须用 IfModule 包裹:模块未加载时裸写指令会导致整站 500
    # --------------------------
    <IfModule mod_expires.c>
        <FilesMatch "\.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$">
            ExpiresActive On
            ExpiresDefault "access plus 30 days"
        </FilesMatch>
    </IfModule>
    
  • NGINX伪静态

    # CmsPro Nginx 伪静态配置(运行目录为项目根)
    # 将以下内容添加到站点 server 块中
    
    # 核心:Laravel URL 重写规则(与 public 场景相比仅此处不同:候选路径加 /public 前缀)
    location / {
        try_files /public$uri /index.php?$query_string;
    }
    
    # 禁止访问隐藏文件(.env、.git 等),允许 .well-known
    location ~ /\.(?!well-known).* {
        deny all;
    }
    
    # 上传目录禁止执行 PHP(安全加固)
    location ~* ^/Uploads/.*\.php$ {
        deny all;
    }
    
    # 静态资源长期缓存(30 天)
    # 根目录运行时本 location 优先于 location / 命中,必须同样映射到 public/ 才能找到资源
    location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$ {
        expires 30d;
        add_header Cache-Control "public, immutable";
        access_log off;
        try_files /public$uri =404;
    }
    
  • IIS伪静态

    <?xml version="1.0" encoding="UTF-8"?>
    <configuration>
        <system.webServer>
            <rewrite>
                <rules>
                    <!-- 上传目录禁止执行 PHP -->
                    <rule name="CmsPro uploads PHP deny" stopProcessing="true">
                        <match url="^(public/)?uploads/.*\.php$" ignoreCase="true" />
                        <action type="CustomResponse" statusCode="403" statusReason="Forbidden" statusDescription="Forbidden" />
                    </rule>
    
                    <!-- 显式请求 /public/ 下的真实文件(安装入口等)时直接交给 IIS -->
                    <rule name="CmsPro public files" stopProcessing="true">
                        <match url="^public/(.+)$" />
                        <conditions>
                            <add input="{REQUEST_FILENAME}" matchType="IsFile" />
                        </conditions>
                        <action type="None" />
                    </rule>
    
                    <!-- 根目录资源 URL 映射到 public\ 下;PHP 文件不作为静态资源映射 -->
                    <rule name="CmsPro public assets" stopProcessing="true">
                        <match url="^(.+)$" />
                        <conditions logicalGrouping="MatchAll">
                            <add input="{APPL_PHYSICAL_PATH}public\{R:1}" matchType="IsFile" />
                            <add input="{R:1}" pattern="\.php$" negate="true" />
                        </conditions>
                        <action type="Rewrite" url="public/{R:1}" appendQueryString="true" />
                    </rule>
    
                    <!-- Laravel URL 重写(其余请求转发到 index.php,与 public 场景相比仅少了 IsFile/IsDirectory 条件) -->
                    <rule name="Laravel to index.php" stopProcessing="true">
                        <match url="^(.*)$" />
                        <action type="Rewrite" url="index.php" appendQueryString="true" />
                    </rule>
                </rules>
            </rewrite>
    
            <!-- 禁止访问隐藏文件 -->
            <security>
                <requestFiltering>
                    <hiddenSegments applyToWebDAV="false">
                        <add segment=".env" />
                        <add segment=".git" />
                        <add segment=".svn" />
                    </hiddenSegments>
                </requestFiltering>
            </security>
    
            <!-- 上传目录禁止执行 PHP -->
            <location path="Uploads">
                <system.webServer>
                    <handlers>
                        <remove name="PHP_via_FastCGI" />
                        <remove name="PHP7_via_FastCGI" />
                        <remove name="PHP8_via_FastCGI" />
                    </handlers>
                </system.webServer>
            </location>
    
            <!-- 静态资源缓存(30 天) -->
            <staticContent>
                <clientCache cacheControlMode="UseMaxAge" cacheControlMaxAge="30.00:00:00" cacheControlCustom="public, immutable" />
            </staticContent>
        </system.webServer>
    </configuration>
    
CMSPRO官方工作人员账号!

全部评论 0

暂无评论,快来发表第一条回复吧!
请先 登录 后再回复