跳到主内容
UniKit

.htaccess 生成

生成 Apache .htaccess 配置:强制 HTTPS、去或加 www、SPA 回退、301/302 重定向、缓存头、gzip、安全响应头、目录密码保护、自定义错误页以及屏蔽 User-Agent 与 IP。

浏览器本地运行所有计算都在你的浏览器里完成,数据不会离开本机。

需求设置

www 处理
强制 HTTPS
SPA history 回退
静态资源缓存头
gzip 压缩
安全响应头
目录密码保护

提示

.htaccess

把内容保存到站点根目录的 .htaccess;改动后用 curl -I 检查响应头是否生效。

# 由 UniKit 生成:Apache .htaccess
# 需要 mod_rewrite / mod_headers / mod_deflate / mod_expires / mod_auth_basic 模块支持

<IfModule mod_rewrite.c>
    RewriteEngine On

    # 强制 HTTPS
    RewriteCond %{HTTPS} !=on
    RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

    # 去掉 www
    RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
    RewriteRule ^ https://%1%{REQUEST_URI} [L,R=301]

    # SPA 回退:真实文件与目录直接返回,其余交给 index.html
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule ^ index.html [L]
</IfModule>

# 静态资源缓存
<IfModule mod_expires.c>
    ExpiresActive On
    ExpiresByType text/css "access plus 30 days"
    ExpiresByType application/javascript "access plus 30 days"
    ExpiresByType image/png "access plus 30 days"
    ExpiresByType image/jpeg "access plus 30 days"
    ExpiresByType image/svg+xml "access plus 30 days"
    ExpiresByType font/woff2 "access plus 30 days"
</IfModule>
<IfModule mod_headers.c>
    <FilesMatch "\.(css|js|mjs|png|jpe?g|gif|webp|avif|svg|ico|woff2?|ttf)$">
        Header set Cache-Control "public, max-age=2592000, immutable"
    </FilesMatch>
</IfModule>

# gzip 压缩
<IfModule mod_deflate.c>
    AddOutputFilterByType DEFLATE text/html text/plain text/css text/xml application/javascript application/json application/xml image/svg+xml
</IfModule>

# 安全响应头
<IfModule mod_headers.c>
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Referrer-Policy "strict-origin-when-cross-origin"
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains" env=HTTPS
</IfModule>

# 自定义错误页
ErrorDocument 404 /404.html

统计

RewriteRule 条数3
指令块5
行数51

这个工具能做什么

  • 给静态站点补上「http 跳 https」和「去 www」:两条 RewriteCond + RewriteRule 就能统一域名,避免同一页面出现多个地址。
  • 前端路由项目(Vue Router / React Router)配置 history 回退,让直接访问 /user/1 这类路径时返回 index.html 而不是 404。
  • 迁移站点时批量加 301:把 /old-page 到新地址的重定向规则一次性写进 .htaccess,搜索引擎会把权重带到新地址。
  • 加缓存、压缩与安全响应头:静态资源按天数加 Cache-Control 与 Expires,文本类型走 gzip,并补上 nosniff、X-Frame-Options 与 HSTS。
  • 做临时预览或后台:用目录密码保护加 Require valid-user,再屏蔽指定 User-Agent 与 IP 段,不装额外模块就能生效。

示例

输入

强制 HTTPS + 去掉 www + SPA 回退,错误页 404 指向 /404.html(关闭缓存、gzip 与安全头)

输出

# 由 UniKit 生成:Apache .htaccess
# 需要 mod_rewrite / mod_headers / mod_deflate / mod_expires / mod_auth_basic 模块支持

<IfModule mod_rewrite.c>
    RewriteEngine On

    # 强制 HTTPS
    RewriteCond %{HTTPS} !=on
    RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

    # 去掉 www
    RewriteCond %{HTTP_HOST} ^www\.(.+)$ [NC]
    RewriteRule ^ https://%1%{REQUEST_URI} [L,R=301]

    # SPA 回退:真实文件与目录直接返回,其余交给 index.html
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteRule ^ index.html [L]
</IfModule>

# 自定义错误页
ErrorDocument 404 /404.html

重定向放在 SPA 回退之前,否则所有路径都会被 index.html 吃掉;去 www 的目标地址会跟随是否强制 HTTPS 自动选 http 或 https。

常见问题

.htaccess 放在哪个目录?

放在站点根目录(DocumentRoot)下,Apache 需要该目录开启 AllowOverride All 才会读取。子目录里也可以再放一份,指令会叠加生效,调试时先确认 mod_rewrite 已启用。

为什么强制 HTTPS 和去 www 要写两条规则?

它们处理的是两个不同条件:HTTPS 判断 %{HTTPS} 是否为 on,www 判断 %{HTTP_HOST} 是否以 www. 开头。都开启时会按顺序执行,最终统一跳到一个地址,避免出现 http://www 这种中间状态。

SPA 回退和重定向规则会打架吗?

不会,但顺序很重要。工具把重定向规则写在 SPA 回退之前,只有不匹配任何重定向、又不是真实文件或目录的路径才会落到 index.html。如果反了,重定向会被回退规则拦掉。

屏蔽 IP 用的是什么语法?

用的是 Apache 2.4 的 <RequireAll> 写法:先 Require all granted,再逐条 Require not ip 203.0.113.5 或 Require not ip 198.51.100.0/24。老版本 2.2 的 Order deny,allow 语法已不再推荐。

密码保护的 .htpasswd 从哪来?

AuthUserFile 指向服务器上的密码文件,用 htpasswd -c /var/www/.htpasswd 用户名 生成。密码文件必须放在网站根目录之外,否则可能被直接下载。

关键词:htaccessapacheredirectrewrite rulebasic authhtaccess 生成Apache 配置重定向伪静态密码保护

同类工具