2010-10-29 37 views
3

我在根目录的子目录中有magento,如果我将安全基础url和安全基础url链接设置为正确的共享ssl url以启用安全页面,我在FRONTEND中没有问题。页面显示为他们应该。但是,当我尝试访问具有以下安全链接的管理员时,我无法获得准入。Url重写导致Magento管理员变得无法访问

例如在前端:http://mydomain.com/shop变为http://mydomain.com - 这是正确的。

https://mydomain.sharedssl.com/shop/customer/account/login/变成 https://mydomain.sharedssl.com/customer/account/login/ - 这是正确的。

但后来我可以既不https://mydomain.com/shop/index.php/admin/也不https://mydomain.com//index.php/admin/

在根目录下我在我的htaccess有这样的访问管理:

RewriteEngine On 
RewriteBase/
RewriteCond %{REQUEST_URI} !^/shop(.*) 
RewriteRule (.*) /shop/$1 [L] 

,并在店(Magento的),我有以下几点:

############################################ 
## uncomment these lines for CGI mode 
## make sure to specify the correct cgi php binary file name 
## it might be /cgi-bin/php-cgi 

# Action php5-cgi /cgi-bin/php5-cgi 
# AddHandler php5-cgi .php 

############################################ 
## GoDaddy specific options 

# Options -MultiViews 

## you might also need to add this line to php.ini 
##  cgi.fix_pathinfo = 1 
## if it still doesn't work, rename php.ini to php5.ini 

############################################ 
## this line is specific for 1and1 hosting 

    #AddType x-mapp-php5 .php 
    #AddHandler x-mapp-php5 .php 

############################################ 
## default index file 

    DirectoryIndex index.php 

<IfModule mod_php5.c> 

############################################ 
## adjust memory limit 

# php_value memory_limit 64M 
    php_value memory_limit 128M 
    php_value max_execution_time 18000 

############################################ 
## disable magic quotes for php request vars 

    php_flag magic_quotes_gpc off 

############################################ 
## disable automatic session start 
## before autoload was initialized 

    php_flag session.auto_start off 

############################################ 
## enable resulting html compression 

    #php_flag zlib.output_compression on 

########################################### 
# disable user agent verification to not break multiple image upload 

    php_flag suhosin.session.cryptua off 

########################################### 
# turn off compatibility with PHP4 when dealing with objects 

    php_flag zend.ze1_compatibility_mode Off 

</IfModule> 

<IfModule mod_security.c> 
########################################### 
# disable POST processing to not break multiple image upload 

    SecFilterEngine Off 
    SecFilterScanPOST Off 
</IfModule> 

<IfModule mod_deflate.c> 

############################################ 
## enable apache served files compression 
## http://developer.yahoo.com/performance/rules.html#gzip 

    # Insert filter on all content 
    ###SetOutputFilter DEFLATE 
    # Insert filter on selected content types only 
    #AddOutputFilterByType DEFLATE text/html text/plain text/xml text/css text/javascript 

    # Netscape 4.x has some problems... 
    #BrowserMatch ^Mozilla/4 gzip-only-text/html 

    # Netscape 4.06-4.08 have some more problems 
    #BrowserMatch ^Mozilla/4\.0[678] no-gzip 

    # MSIE masquerades as Netscape, but it is fine 
    #BrowserMatch \bMSIE !no-gzip !gzip-only-text/html 

    # Don't compress images 
    #SetEnvIfNoCase Request_URI \.(?:gif|jpe?g|png)$ no-gzip dont-vary 

    # Make sure proxies don't deliver the wrong content 
    #Header append Vary User-Agent env=!dont-vary 

</IfModule> 

<IfModule mod_ssl.c> 

############################################ 
## make HTTPS env vars available for CGI mode 

    #SSLOptions StdEnvVars 

</IfModule> 

<IfModule mod_rewrite.c> 

############################################ 
## enable rewrites 

    Options +FollowSymLinks 
    RewriteEngine on 

############################################ 
## you can put here your magento root folder 
## path relative to web root 

    RewriteBase/


############################################ 
## workaround for HTTP authorization 
## in CGI environment 

    RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}] 

############################################ 
## always send 404 on missing files in these folders 

    RewriteCond %{REQUEST_URI} !^/(media|skin|js)/ 

############################################ 
## never rewrite for existing files, directories and links 

    RewriteCond %{REQUEST_FILENAME} !-f 
    RewriteCond %{REQUEST_FILENAME} !-d 
    RewriteCond %{REQUEST_FILENAME} !-l 

############################################ 
## rewrite everything else to index.php 

    RewriteRule ^(.*)$ /shop/index.php [L] 



</IfModule> 


############################################ 
## Prevent character encoding issues from server overrides 
## If you still have problems, use the second line instead 

    AddDefaultCharset Off 
    #AddDefaultCharset UTF-8 

<IfModule mod_expires.c> 

############################################ 
## Add default Expires header 
## http://developer.yahoo.com/performance/rules.html#expires 

    ExpiresDefault "access plus 1 year" 

</IfModule> 

############################################ 
## By default allow all access 

    Order allow,deny 
    Allow from all 

############################################ 
## If running in cluster environment, uncomment this 
## http://developer.yahoo.com/performance/rules.html#etags 

    #FileETag none 

有人可以借助一些帮助让它在Magento后端工作吗?

+0

您可以发布此请求的结果:'SELECT * FROM core_config_data WHERE path like'%url'' – greg0ire 2010-10-30 10:54:53

回答

1

问题在于得到REQUEST_URI环境变量值并使用SCRIPT_FILENAMESCRIPT_NAME环境变量值对其进行检查。在你的情况下,REQUEST_URI是/index.php/stddadmin/,而SCRIPT_NAME的SCRIPT_FILENAME等于/shop/index.php,而Magento无法检索匹配控制器的路径信息。所以问题的一个原因是在请求路径中添加了/index.php/前缀,并且Magento网址生成的admin值为该硬编码值。

只有两种解决方案,您的问题:

  1. 覆盖方法Mage_Core_Model_Store模型就像下面这个例子叫_updatePathUseRewrites

    class Your_CustomModule_Model_Store extends Mage_Core_Model_Store 
    { 
        protected _updatePathUseRewrites($url) 
        { 
         return $url; // Return passed variable without adding index.php as prefix 
        } 
    } 
    

    在这种情况下,你的管理面板将可在/ admin/url,就像通常的前端页面一样。

  2. 重新组织项目结构,将Magento放置在根文件夹中或在其根目录中的每个文件和文件夹上添加符号链接。
+0

谢谢你的回应。我所做的就是允许共享ssl保持原样,它允许我登录到后端,但也显示在前端。所以我改变了主要网站不安全和安全的基地网站和事情开始工作。 – capnhud 2010-11-04 11:06:58