顯示具有 .htaccess 標籤的文章。 顯示所有文章
顯示具有 .htaccess 標籤的文章。 顯示所有文章

2011年12月21日 星期三

[.htaccess] 設定記錄

老了, 記憶力越來越不可靠, 還是要記錄下來.

用途: 把前端帶有  xx 或 zh-TW/xx 或 zh-CN/xx 或 ja/xx 而後面接downloadstart 導到 $1 頁面.

RewriteRule ^(xx|zh-TW/xx|zh-CN/xx|ja/xx)/downloadstart.*$  $1/ [L]


用途: 過濾 REQUEST_URI 不等於 上面三個 RewriteCond 就導引到 /download/xxx.exe
RewriteCond %{REQUEST_URI} !oem/.+\.exe$ [NC]
RewriteCond %{REQUEST_URI} !pro/.+\.exe$ [NC]
RewriteCond %{REQUEST_URI} !test.exe$ [NC]
RewriteRule ^(.+)\.exe$ /download/xxx.exe [R=301,NC,L]

持續增加...

2011年9月14日 星期三

[引用].htaccess ErrorDocument 使用方式

來源:http://businesswing.net/webdesign/php-htaccess_to_do_system_protection/

網站伺服器在不能回應使用者需求下,會產生各種錯誤訊息,這些錯誤訊息均有一個代碼,我們來瞧瞧這代碼所代表的意義:
回應代碼 回應內容 代表意義
401 Authorization failed 授權失敗。使用者輸入的帳號密碼無法得到授權。
403 Forbidden 存取控制機制拒絕使用者的請求,也就是說你不可以讀取這個檔案。
404 File not found 被要求的網頁不存在於這個伺服器上,找不到檔案。
500 Internal Server Error 伺服器內部錯誤;可能是網站伺服器或PHP出了問題。
501 Not Implemented 伺服器不瞭解資料傳遞的方式。
503 Service Unavailable 這個伺服器目前正在處理太多的服務要求。
php_ch10-19
【圖19、找不到檔案時顯示方式】

如果我們想要自訂錯誤訊息呢?要設定錯誤頁,請在.htaccess中輸入
ErrorDocument 錯誤代碼 /網站根目錄開始的資料夾/檔名
例如當使用者找不到網頁時,會產生404錯誤的回傳,請在.htaccess內加入以下資料:
ErrorDocument 404 /error/notfound.htm
當使用者在瀏覽不存在的網頁時,就會自動轉向至localhost(或你的網站ip)/error/notfound.htm,
php_ch10-20
【圖20、自訂找不到檔案時顯示的內容】

所以您可針對上述的錯誤情形,在.htaccess內加入多行的語法:
ErrorDocument 401 /errors/authreqd.html
ErrorDocument 403 /errors/forbid.html
ErrorDocument 404 /errors/notfound.html
ErrorDocument 500 /errors/serverr.html
除了指向目錄內的網頁外,您也可以指向一個網址,就可以多個網站共用相同的錯誤訊息,再以找不到網頁時,會產生404錯誤的回傳,您可在.htaccess內加入以下資料:
ErrorDocument也可接一段文字或者直接指定一段html語法,但是,文字或html必須與ErrorDocument是同一行。找不到網頁時,希望顯示文字,您可在.htaccess內加入以下資料:
ErrorDocument 404 "Page not found!!"
找不到網頁時,希望顯示網頁,您可在.htaccess內加入以下資料:

ErrorDocument 404 "<h1><i>Page not found!!</i></h1>"

php_ch10-21
【圖21、自訂找不到檔案時顯示的內容】

另外:  若是因為絕對路徑與相對路徑的問題.
最好在前面加個 Alias 去把 /error/ 的路徑定義出來.  否則可能會因為路徑錯誤而找不到檔案.

Alias /errors/  "/var/www/web4/web/error/"
ErrorDocument 401 /errors/error.html


2011年4月1日 星期五

.htaccess 快取網站圖片, js , CSS , png ,gif

利用 .htaccess 來達成 圖片與js 檔案 304 cache .


# 快取一年
<FilesMatch "\.(ico|pdf|flv)$">
Header set Cache-Control "max-age=29030400, public"
</FilesMatch>
# 快取一周
<FilesMatch "\.(jpg|jpeg|png|gif|swf)$">
Header set Cache-Control "max-age=604800, public"
</FilesMatch>
# 快取二天
<FilesMatch "\.(xml|txt|css|js)$">
Header set Cache-Control "max-age=172800, proxy-revalidate"
</FilesMatch>
# 快取一分鐘
<FilesMatch "\.(html|htm|php)$">
Header set Cache-Control "max-age=60, private, proxy-revalidate"
</FilesMatch>
#FileETag MTime Size mod_expires 可以指定副檔名- 用以下兩個方式, 當檔案有改變時,會再重新讀取. <ifmodule mod_expires.c> <filesmatch "\.(jpg|gif|png|css|js)$"> ExpiresActive on ExpiresDefault "access plus 1 year" </filesmatch> </ifmodule> # Requires mod_expires to be enabled. 不只定副檔名 <IfModule mod_expires.c> # Enable expirations. ExpiresActive On # Cache all files for 2 weeks after access (A). ExpiresDefault A1209600 # Do not cache dynamically generated pages. ExpiresByType text/html A1 </IfModule>


很詳細的說明: http://betterexplained.com/articles/how-to-optimize-your-site-with-http-caching/
參考網站 :http://www.askapache.com/htaccess/speed-up-sites-with-htaccess-caching.html

2010年9月16日 星期四

Custom HTTP Headers P3P

來源網站

100% Prevent Files from being cached

This is similar to how google ads employ the header Cache-Control: private, x-gzip-ok="" to prevent caching of ads by proxies and clients.

<FilesMatch "\.(html|htm|js|css)$">
FileETag None
<IfModule mod_headers.c>
Header unset ETag
Header set Cache-Control "max-age=0, no-cache, no-store, must-revalidate"
Header set Pragma "no-cache"
Header set Expires "Wed, 11 Jan 1984 05:00:00 GMT"
</IfModule>
</FilesMatch>

Remove IE imagetoolbar

<FilesMatch "\.(html|htm)$">
<IfModule mod_headers.c>
Header set imagetoolbar "no"
</IfModule>
</FilesMatch>

Add P3P Privacy Headers to your site

Adding a P3P header to your site is a good idea, do this.

<IfModule mod_headers.c>
Header set P3P "policyref=\"/w3c/p3p.xml\", CP=\"NOI DSP COR NID CUR ADM DEV OUR BUS\""
# OR THIS, SIMPLER
Header set P3P "policyref=\"/w3c/p3p.xml\""
</IfModule>

Add a 「en-US」 language header and UTF-8 without meta tags!

Article: Setting Charset in htaccess

AddDefaultCharset UTF-8
AddLanguage en-US .html .htm .css .js

Using AddType

AddType 'text/html; charset=UTF-8' .html

Using the Files Directive

Article: Using 『Files』 in htaccess

<Files ~ "\.(htm|html|css|js)$">
AddDefaultCharset UTF-8
DefaultLanguage en-US
</Files>

Using the FilesMatch Directive

Article: Using 『FilesMatch』 in htaccess

<FilesMatch "\.(htm|html|css|js)$">
AddDefaultCharset UTF-8
DefaultLanguage en-US
</FilesMatch>

Example - This is how Yahoo has it setup even though they're not dealing with FB iframe issues presumably.

HTTP header included in all HTTP requests made using IE 6+

P3P: policyref="http://info.yahoo.com/w3c/p3p.xml", CP="CAO DSP COR CUR ADM DEV TAI PSA PSD IVAi IVDi CONi TELo OTPi OUR DELi SAMi OTRi UNRi PUBi IND PHY ONL UNI PUR FIN COM NAV INT DEM CNT STA POL HE

Referenced P3P XML file

http://info.yahoo.com/w3c/p3p.xml which redirects to http://info.yahoo.com/privacy/w3c/p3p_policy.xml


Server Configuration - Easiest way is to setup Apache to add P3P header to all HTTP calls made from an IE browser

Add the following to your httpd.conf file within settings. More about that here http://httpd.apache.org/docs/2.0/mod/mod_headers.html

BrowserMatch MSIE IS_MSIE
Header set P3P "policyref=\"http://www.your-domain.com/w3c/p3p.xml\", CP=\"CAO DSP CURa ADMa DEVa TAIa PSAa PSDa IVAi IVDi CONi OUR UNRi OTRi BUS IND PHY ONL UNI COM NAV INT DEM CNT STA PRE GOV LOC\"" env=IS_MSIE

The value of the CP portion can be generated using IBM's tool (link above)

Hope this helps. With this setup you'll be able to set cookies and use cookie-based session management even when IE is set to use highest privacy settings (Medium are the default)

SESSION / COOKIES in IFRAME 解決辦法

.htaccess file:
Header append P3P 'CP="OURPOLICYINFO"'

ASP:
Response.AddHeader "P3P", "CP=CAO PSA OUR"

php:
header('P3P: CP=CAO PSA OUR');

ASP.NET
通過在代碼上加
Response.AddHeader("P3P", "CP=CAO PSA OUR")
或者在Window服務中將ASP.NET State Service 啟動。

JSP:
response.setHeader("P3P","CP=CAO PSA OUR")


這樣就可以抓取的到 session / cookie

2010年6月8日 星期二

檢測.htaccess 是否啟用.

第一:檢測 apache是否開啟mod_rewrite
通過php提供的phpinfo()函數查看環境配置,在「apache2handler —> Loaded Modules」裡看是否有「mod_rewrite」模塊,如沒開啟則在apache配置文件httpd.conf 中找到「#LoadModule rewrite_module modules/mod_rewrite.so」去掉前面的「#」號,重啟apache即可

第二:檢測apache是否支持「.htaccess」
如測試中不支持「.htaccess」,那在apache配置文件httpd.conf 中找到「」與「」內的「AllowOverride None」改為「AllowOverride All」,重啟apache即可

第三:創建.htaccess 文件
創建.htaccess 文件方法:新建文本文檔,名字為「htaccess.txt」,再打開「htaccess.txt」另存為,此時注意,名稱改為 「」.htaccess」」保存即可

第四:測試偽靜態實例
.htaccess文件中輸入:
RewriteEngine on
RewriteRule ([a-zA-Z]{1,})-([0-9]{1,})-([0-9]{1,})\.html$ index.php?action=$1&id=$2&page=$3
新建index.php文件並輸入:

<?php
echo "action=".$_GET['action'];
echo "<br>id=".$_GET['id'];
echo "<br>page=".$_GET['page'];
?>


在地址欄中輸入 http://127.0.0.1/view-8-2.html 按重新整理將顯示出參數:
action=view
id=8
page=2