You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在不暴露Zoom access_token的前提下高效在前端展示Zoom录制视频?

安全且高性能展示Zoom录制视频的解决方案

针对你遇到的「暴露access_token不安全」和「代理转发拖慢性能」的问题,有两种靠谱的解决思路:

方案1:用Zoom API生成临时播放链接(推荐)

Zoom官方提供了生成带有效期的临时访问链接的能力,全程在服务端操作,不会把access_token暴露给前端,同时视频直接从Zoom的CDN加载,性能和直接播放无差异。

实现步骤:

  1. 后端通过Server-to-Server OAuth获取合法的access_token(全程在服务端执行,绝不传到前端)。
  2. 调用Zoom的GET /meetings/{meetingId}/recordings接口,拿到对应录制文件的详情。
  3. 从返回的recording_files数组中找到MP4格式的文件,调用Zoom的分享接口(POST /meetings/{meetingId}/recordings/share)生成一个带有效期的临时播放链接(比如设置1小时有效期)。
  4. 把这个临时链接传给前端,作为<video>标签的src值。

代码示例:

后端PHP(生成临时链接):

// 已有的Server-to-Server OAuth获取access_token逻辑
$access_token = get_zoom_server_token();

// 假设你已经拿到了meeting_id
$meeting_id = 'xxxxxx';

// 请求录制文件详情
$ch = curl_init("https://api.zoom.us/v2/meetings/{$meeting_id}/recordings");
curl_setopt($ch, CURLOPT_HTTPHEADER, [
    "Authorization: Bearer {$access_token}",
    "Content-Type: application/json"
]);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$recording_response = curl_exec($ch);
curl_close($ch);
$recording_data = json_decode($recording_response, true);

// 生成临时分享链接(以MP4文件为例)
$share_payload = json_encode([
    "share_recording" => [
        "enable" => true,
        "expire_time" => date('Y-m-d\TH:i:s\Z', strtotime('+1 hour')) // 1小时后过期
    ]
]);

$ch = curl_init("https://api.zoom.us/v2/meetings/{$meeting_id}/recordings/share");
curl_setopt($ch, CURLOPT_HTTPHEADER, [
    "Authorization: Bearer {$access_token}",
    "Content-Type: application/json"
]);
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, $share_payload);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
$share_response = curl_exec($ch);
curl_close($ch);
$share_data = json_decode($share_response, true);

// 拿到临时播放链接
$temporary_play_url = $share_data['share_url'];

前端HTML:

<video width="780" height="480" controls>
    <source src="<?php echo $temporary_play_url; ?>" type="video/mp4">
    Your browser does not support the video
</video>

方案2:反向代理+本地缓存

如果无法使用Zoom的临时分享功能,可以通过反向代理隐藏access_token,同时配合缓存解决性能问题。

实现思路:

  1. 用Nginx(或其他反向代理工具)搭建一个代理服务,配置中加入Zoom的access_token(只在服务器端保存)。
  2. 前端请求视频时,直接访问代理服务的URL,代理自动在请求头中带上access_token转发给Zoom。
  3. 配置代理的缓存规则,把Zoom返回的视频文件缓存到本地服务器或CDN,后续相同请求直接返回缓存内容,不用再调用Zoom API。

Nginx配置示例:

# 定义缓存目录和规则
proxy_cache_path /var/cache/zoom-recordings levels=1:2 keys_zone=zoom_cache:10m max_size=10g inactive=7d use_temp_path=off;

server {
    # ...其他配置...

    location /zoom-rec/ {
        # 启用缓存
        proxy_cache zoom_cache;
        proxy_cache_valid 200 7d; # 缓存有效视频7天
        proxy_cache_key "$request_uri";

        # 转发请求到Zoom,添加access_token
        proxy_pass https://us02web.zoom.us/rec/download/;
        proxy_set_header Authorization "Bearer YOUR_SERVER_ACCESS_TOKEN";

        # 允许前端跨域(如果你的前端和代理不在同一域名)
        add_header Access-Control-Allow-Origin *;
    }
}

前端HTML:

<video width="780" height="480" controls>
    <source src="/zoom-rec/<?php echo $download_path; ?>" type="video/mp4">
    Your browser does not support the video
</video>

这两种方案都能满足「隐藏access_token」和「不降低性能」的要求,方案1更贴合Zoom的原生能力,推荐优先使用。

内容的提问来源于stack exchange,提问作者Aadhil Ahamed

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 10:38:08