{"id":35476,"date":"2019-10-31T22:04:32","date_gmt":"2019-10-31T19:04:32","guid":{"rendered":"https:\/\/prohoster.info\/blog\/retsepty-nginx-basic-avtorizatsiya-s-kapchej\/"},"modified":"2019-10-31T22:04:32","modified_gmt":"2019-10-31T19:04:32","slug":"retsepty-nginx-basic-avtorizatsiya-s-kapchej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/retsepty-nginx-basic-avtorizatsiya-s-kapchej","title":{"rendered":"Re\u021bete Nginx: autorizare basic cu CAPTCHA","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Pentru a preg\u0103ti autentificarea cu CAPTCHA, avem nevoie de ea <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/RekGRpth\/nginx\">nginx<\/a><\/noindex> \u0219i pluginurile sale <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/RekGRpth\/encrypted-session-nginx-module\">encrypted-session<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/RekGRpth\/form-input-nginx-module\">form-input<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/RekGRpth\/ngx_ctpp2\">ctpp2<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/RekGRpth\/echo-nginx-module\">echo<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/RekGRpth\/headers-more-nginx-module\">headers-more<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/nginx.org\/ru\/docs\/http\/ngx_http_auth_request_module.html\">auth_request<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/nginx.org\/ru\/docs\/http\/ngx_http_auth_basic_module.html\">auth_basic<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/RekGRpth\/set-misc-nginx-module\">set-misc<\/a><\/noindex>. (Am inclus linkuri c\u0103tre fork-urile mele, deoarece am f\u0103cut unele modific\u0103ri care \u00eenc\u0103 nu au fost integrate \u00een repozitoriile originale. Se poate, de asemenea, utiliza <noindex><a rel=\"nofollow\" href=\"https:\/\/hub.docker.com\/r\/rekgrpth\/nginx\">o form\u0103 gata<\/a><\/noindex>.)<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\nLa \u00eenceput, s\u0103 set\u0103m <\/p>\n<pre><code class=\"nginx\">encrypted_session_key \"abcdefghijklmnopqrstuvwxyz123456\";<\/code><\/pre>\n<p>\nMai departe, pentru siguran\u021b\u0103, dezactiv\u0103m antetul de autentificare <\/p>\n<pre><code class=\"nginx\">more_clear_input_headers Authorization;<\/code><\/pre>\n<p>\nAcum protej\u0103m totul cu autentificare <\/p>\n<pre><code class=\"nginx\">auth_request \/auth;\nlocation =\/auth {\n    internal;\n    subrequest_access_phase on; # permite faza de autorizare \u00een subcerere\n    auth_request off; # nu folosi autorizarea\n    set_decode_base64 $auth_decode $cookie_auth; # decodific\u0103m cookie-ul de autorizare\n    set_decrypt_session $auth_decrypt $auth_decode; # decript\u0103m sesiunea de autorizare\n    if ($auth_decrypt = \"\") { return 401 UNAUTHORIZED; } # dac\u0103 nu s-a reu\u0219it decriptarea, \u00eenseamn\u0103 c\u0103 utilizatorul nu este autorizat\n    more_set_input_headers \"Authorization: Basic $auth_decrypt\"; # \u00eenlocuim autorizarea cu basic (pentru a folosi variabila $remote_user)\n    auth_basic_user_file \/data\/nginx\/.htaccess; # set\u0103m fi\u0219ierul de autorizare basic\n    auth_basic Auth; # activ\u0103m autorizarea basic\n    echo -n OK; # utilizator autorizat\n}<\/code><\/pre>\n<p>\nPentru utilizatorii autoriza\u021bi, afi\u0219\u0103m con\u021binutul din folderul lor <\/p>\n<pre><code class=\"nginx\">location \/ {\n    alias html\/$remote_user\/;\n}<\/code><\/pre>\n<p>\nIar \u00een lipsa autentific\u0103rii, afi\u0219\u0103m formularul de autentificare cu CAPTCHA <\/p>\n<pre><code class=\"nginx\">error_page 401 = @error401;\nlocation @error401 {\n    set_escape_uri $request_uri_escape $request_uri; # codific\u0103m cererea\n    return 303 \/login?request_uri=$request_uri_escape; # redirec\u021bion\u0103m c\u0103tre formularul de autentificare cu CAPTCHA, p\u0103str\u00e2nd cererea\n}\nlocation =\/login {\n    default_type \"text\/html; charset=utf-8\"; # set\u0103m tipul\n    if ($request_method = GET) { # dac\u0103 doar dorim s\u0103 afi\u0219\u0103m formularul de autentificare cu CAPTCHA\n        template login.html.ct2; # set\u0103m \u0219ablonul\n        ctpp2 on; # activ\u0103m motorul de \u0219ablonizare\n        set_secure_random_alphanum $csrf_random 32; # gener\u0103m un CSRF aleator\n        encrypted_session_expires 300; # set\u0103m durata de via\u021b\u0103 a CSRF-ului la 5 minute (5 * 60 = 300)\n        set_encrypt_session $csrf_encrypt $csrf_random; # cript\u0103m CSRF-ul aleator\n        set_encode_base64 $csrf_encode $csrf_encrypt; # codific\u0103m CSRF-ul criptat\n        add_header Set-Cookie \"CSRF=$csrf_encode; Max-Age=300\"; # stoc\u0103m CSRF-ul criptat \u00eentr-un cookie pentru 5 minute (5 * 60 = 300)\n        return 200 \"{\"csrf\":\"$csrf_random\"}\"; # return\u0103m JSON pentru motorul de \u0219ablonizare\n    } # altfel - proces\u0103m formularul de autentificare cu CAPTCHA\n    set_form_input $csrf_form csrf; # ob\u021binem CSRF-ul din formular\n    set_unescape_uri $csrf_unescape $csrf_form; # decodific\u0103m CSRF-ul din formular\n    set_decode_base64 $csrf_decode $cookie_csrf; # decodific\u0103m CSRF-ul din cookie\n    set_decrypt_session $csrf_decrypt $csrf_decode; # decript\u0103m CSRF-ul din cookie\n    if ($csrf_decrypt != $csrf_unescape) { return 303 $request_uri; } # dac\u0103 CSRF-ul din formular nu corespunde cu CSRF-ul din cookie, atunci redirec\u021bion\u0103m pentru a ar\u0103ta din nou formularul\n    set_form_input $captcha_form captcha; # ob\u021binem CAPTCHA din formular\n    set_unescape_uri $captcha_unescape $captcha_form; # decodific\u0103m CAPTCHA-ul din formular\n    set_md5 $captcha_md5 \"secret${captcha_unescape}${csrf_decrypt}\"; # calcul\u0103m MD5\n    if ($captcha_md5 != $cookie_captcha) { return 303 $request_uri; } # dac\u0103 MD5-ul nu corespunde cu CAPTCHA-ul din cookie, atunci redirec\u021bion\u0103m pentru a ar\u0103ta din nou formularul\n    set_form_input $username_form username; # ob\u021binem numele de utilizator din formular\n    set_form_input $password_form password; # ob\u021binem parola din formular\n    set_unescape_uri $username_unescape $username_form; # decodific\u0103m numele de utilizator din formular\n    set_unescape_uri $password_unescape $password_form; # decodific\u0103m parola din formular\n    encrypted_session_expires 2592000; # set\u0103m durata de via\u021b\u0103 a sesiunii la 30 de zile (30 * 24 * 60 * 60 = 2592000)\n    set $username_password \"$username_unescape:$password_unescape\"; # set\u0103m autentificarea basic\n    set_encode_base64 $username_password_encode $username_password; # codific\u0103m autentificarea basic\n    set_encrypt_session $auth_encrypt $username_password_encode; # cript\u0103m autentificarea basic\n    set_encode_base64 $auth_encode $auth_encrypt; # codific\u0103m autentificarea basic criptat\u0103\n    add_header Set-Cookie \"Auth=$auth_encode; Max-Age=2592000\"; # stoc\u0103m autentificarea basic criptat\u0103 \u00eentr-un cookie pentru 30 de zile (30 * 24 * 60 * 60 = 2592000)\n    set $arg_request_uri_or_slash $arg_request_uri; # copiem cererea din argument\n    set_if_empty $arg_request_uri_or_slash \"\/\"; # dac\u0103 argumentul nu este specificat, atunci \u00eencepem\n    set_unescape_uri $request_uri_unescape $arg_request_uri_or_slash; # decodific\u0103m cererea\n    return 303 $request_uri_unescape; # redirec\u021bion\u0103m c\u0103tre cererea salvat\u0103\n}<\/code><\/pre>\n<p>\nlogin.html<\/p>\n<pre><code class=\"xml\">&lt;html&gt;\n    &lt;body&gt;\n        &lt;form method=&quot;post&quot; action=&quot;&quot;&gt;\n            &lt;input type=&quot;hidden&quot; name=&quot;csrf&quot; value=&quot;&lt;TMPL_var csrf&gt;&quot; \/&gt;\n            nume de utilizator: &lt;input type=&quot;text&quot; name=&quot;username&quot; placeholder=&quot;Introduceti Numele de Utilizator...&quot; \/&gt;&lt;br \/&gt;\n            parola: &lt;input type=&quot;password&quot; name=&quot;password&quot; \/&gt;&lt;br \/&gt;\n            captcha: &lt;img src=&quot;\/captcha?csrf=&lt;TMPL_var csrf&gt;&quot;\/&gt;&lt;input type=&quot;text&quot; name=&quot;captcha&quot; autocomplete=&quot;off&quot; \/&gt;&lt;br \/&gt;\n            &lt;input type=&quot;submit&quot; name=&quot;submit&quot; value=&quot;trimitere&quot; \/&gt;\n        &lt;input type=&quot;hidden&quot; name=&quot;trp-form-language&quot; value=&quot;ro&quot;\/&gt;&lt;\/form&gt;\n    &lt;\/body&gt;\n&lt;\/html&gt;<\/code><\/pre>\n<p>Sursa: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/456556\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u043b\u044f \u043f\u0440\u0438\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0441 \u043a\u0430\u043f\u0447\u0435\u0439 \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u0441\u0430\u043c nginx \u0438 \u0435\u0433\u043e \u043f\u043b\u0430\u0433\u0438\u043d\u044b encrypted-session, form-input, ctpp2, echo, headers-more, auth_request, auth_basic, set-misc. (\u042f \u0434\u0430\u043b \u0441\u0441\u044b\u043b\u043a\u0438 \u043d\u0430 \u0441\u0432\u043e\u0438 \u0444\u043e\u0440\u043a\u0438, \u0442.\u043a. \u0434\u0435\u043b\u0430\u043b \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043f\u043e\u043a\u0430 \u043d\u0435 \u0443\u0434\u0430\u043b\u043e\u0441\u044c \u043f\u0440\u043e\u043f\u0438\u0445\u043d\u0443\u0442\u044c \u0432 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b\u044c\u043d\u044b\u0435 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0438. \u041c\u043e\u0436\u043d\u043e \u0442\u0430\u043a\u0436\u0435 \u0432\u043e\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0433\u043e\u0442\u043e\u0432\u044b\u043c \u043e\u0431\u0440\u0430\u0437\u043e\u043c.) \u0414\u043b\u044f \u043d\u0430\u0447\u0430\u043b\u0430 \u0437\u0430\u0434\u0430\u0434\u0438\u043c encrypted_session_key &#171;abcdefghijklmnopqrstuvwxyz123456&#187;; \u0414\u0430\u043b\u044c\u0448\u0435, \u043d\u0430 \u0432\u0441\u044f\u043a\u0438\u0439 \u0441\u043b\u0443\u0447\u0430\u0439, \u043e\u0442\u043a\u043b\u044e\u0447\u0430\u0435\u043c \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u043e\u043d\u043d\u044b\u0439 \u0437\u0430\u0433\u043e\u043b\u043e\u0432\u043e\u043a [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-35476","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u043b\u044f \u043f\u0440\u0438\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0441 \u043a\u0430\u043f\u0447\u0435\u0439 \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u0441\u0430\u043c nginx \u0438 \u0435\u0433\u043e \u043f\u043b\u0430\u0433\u0438\u043d\u044b\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/retsepty-nginx-basic-avtorizatsiya-s-kapchej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u0446\u0435\u043f\u0442\u044b Nginx: basic \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044f \u0441 \u043a\u0430\u043f\u0447\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u043b\u044f \u043f\u0440\u0438\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0441 \u043a\u0430\u043f\u0447\u0435\u0439 \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u0441\u0430\u043c nginx \u0438 \u0435\u0433\u043e \u043f\u043b\u0430\u0433\u0438\u043d\u044b\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/retsepty-nginx-basic-avtorizatsiya-s-kapchej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:04:32+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:04:32+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Re\u021bete Nginx: autorizare basic cu captcha | ProHoster","description":"Pentru configurarea autentific\u0103rii cu captcha, avem nevoie de Nginx \u0219i de pluginurile sale.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/retsepty-nginx-basic-avtorizatsiya-s-kapchej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u0446\u0435\u043f\u0442\u044b Nginx: basic \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u044f \u0441 \u043a\u0430\u043f\u0447\u0435\u0439 | ProHoster","og:description":"\u0414\u043b\u044f \u043f\u0440\u0438\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0438 \u0441 \u043a\u0430\u043f\u0447\u0435\u0439 \u043d\u0430\u043c \u043f\u043e\u043d\u0430\u0434\u043e\u0431\u0438\u0442\u0441\u044f \u0441\u0430\u043c nginx \u0438 \u0435\u0433\u043e \u043f\u043b\u0430\u0433\u0438\u043d\u044b","og:url":"https:\/\/prohoster.info\/ro\/blog\/administrirovanie\/retsepty-nginx-basic-avtorizatsiya-s-kapchej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:04:32+00:00","article:modified_time":"2019-10-31T19:04:32+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35476","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 23:26:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:01:27","updated":"2026-01-21 23:26:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/35476","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=35476"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/35476\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=35476"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=35476"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=35476"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}