JFrog Artifactory Groovy插件阻止下载异常:curl仍可下载指定文件
解决JFrog Artifactory Groovy插件阻止下载时curl仍能获取文件的问题
问题背景
需要拦截特定文件名的下载请求(例如包含testmaven-0.0.1-SNAPSHOT.jar的文件),当前使用altResponse钩子编写Groovy插件,UI端拦截生效,但通过curl -O http://xxxxxx/artifactory/cid-maven-local/testmaven-0.0.1-SNAPSHOT.jar请求时,日志显示返回403,但文件仍被下载到本地。
现有插件代码
download { altResponse { request, responseRepoPath -> log.warn("altResponse") def fileName = responseRepoPath.getName() log.warn "altResponse status: ${status},fileName:${fileName}" if (fileName.contains("testmaven-0.0.1-SNAPSHOT.jar")){ log.warn "altResponse name contains: ${fileName}" status = 403 message = "can't download" log.warn "altResponse newstatus: ${status}" }else { log.warn("fileName not contains") } } }
问题原因
altResponse钩子的作用是修改响应内容,触发时机是在Artifactory已经准备好响应内容之后。对于直接的文件下载请求,此时文件内容可能已经开始向客户端传输,修改状态码无法中断传输流程,导致curl仍能接收到文件内容。
解决方案
改用beforeDownloadRequest钩子,这个钩子在请求被处理之前触发,能够直接拦截并终止请求,无论UI还是命令行工具都会生效。
修正后的插件代码:
download { beforeDownloadRequest { request, repoPath -> def fileName = repoPath.getName() log.warn "Checking download request for file: ${fileName}" if (fileName.contains("testmaven-0.0.1-SNAPSHOT.jar")) { log.warn "Blocking download of restricted file: ${fileName}" status = 403 message = "Download of this file is prohibited" } } }
验证步骤
- 将修改后的插件文件替换
artifactory/plugins/目录下的原文件 - 重启Artifactory(或通过Artifactory UI的Plugins页面热加载插件)
- 使用curl命令测试:
curl -O http://xxxxxx/artifactory/cid-maven-local/testmaven-0.0.1-SNAPSHOT.jar - 此时curl会收到403响应,不会下载文件,同时Artifactory日志会记录拦截行为
内容的提问来源于stack exchange,提问作者Kim Chen
相关产品推荐
相关产品推荐

