BaoTa icon indicating copy to clipboard operation
BaoTa copied to clipboard

[改进意见] 当前宝塔的反向代理功能开启后,会影响SSL自动续签

Open xiaohuilam opened this issue 2 years ago • 1 comments

https://github.com/aaPanel/BaoTa/blob/f776b5d154a52da4ae43ab6e3a97ccc32e50bbd4/class/panelSite.py#L2696-L2719

你们可以判读啊用户创建的反代目录规则,如果用户想反代 / (http根路径) 时候,可以将规则替换为

#PROXY-START/

location ~ ^/(?!(.well-known))
{
    proxy_pass https://www.baidu.com;
    proxy_set_header Host www.baidu.com;
    proxy_set_header X-Real-IP $remote_addr;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header REMOTE-HOST $remote_addr;
}

.well-known 排除在反代之外,这样,SSL续签就不受影响了。

xiaohuilam avatar Mar 29 '22 12:03 xiaohuilam

宝塔 github 长时间不维护,从来不回复问题,你们知道什么原因吗?

kooy avatar Sep 12 '22 01:09 kooy