You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JFrog Artifactory Groovy插件阻止下载异常:curl仍可下载指定文件

解决JFrog Artifactory Groovy插件阻止下载时curl仍能获取文件的问题

问题背景

需要拦截特定文件名的下载请求(例如包含testmaven-0.0.1-SNAPSHOT.jar的文件),当前使用altResponse钩子编写Groovy插件,UI端拦截生效,但通过curl -O http://xxxxxx/artifactory/cid-maven-local/testmaven-0.0.1-SNAPSHOT.jar请求时,日志显示返回403,但文件仍被下载到本地。

现有插件代码

download {
    altResponse { request, responseRepoPath ->
        log.warn("altResponse")
        def fileName = responseRepoPath.getName()
        log.warn "altResponse status: ${status},fileName:${fileName}"
        if (fileName.contains("testmaven-0.0.1-SNAPSHOT.jar")){
            log.warn "altResponse name contains: ${fileName}"
            status = 403 
            message = "can't download"
            log.warn "altResponse newstatus: ${status}"
        }else {
            log.warn("fileName not contains")
        }
    }
}

问题原因

altResponse钩子的作用是修改响应内容,触发时机是在Artifactory已经准备好响应内容之后。对于直接的文件下载请求,此时文件内容可能已经开始向客户端传输,修改状态码无法中断传输流程,导致curl仍能接收到文件内容。

解决方案

改用beforeDownloadRequest钩子,这个钩子在请求被处理之前触发,能够直接拦截并终止请求,无论UI还是命令行工具都会生效。

修正后的插件代码:

download {
    beforeDownloadRequest { request, repoPath ->
        def fileName = repoPath.getName()
        log.warn "Checking download request for file: ${fileName}"
        if (fileName.contains("testmaven-0.0.1-SNAPSHOT.jar")) {
            log.warn "Blocking download of restricted file: ${fileName}"
            status = 403
            message = "Download of this file is prohibited"
        }
    }
}

验证步骤

  1. 将修改后的插件文件替换artifactory/plugins/目录下的原文件
  2. 重启Artifactory(或通过Artifactory UI的Plugins页面热加载插件)
  3. 使用curl命令测试:curl -O http://xxxxxx/artifactory/cid-maven-local/testmaven-0.0.1-SNAPSHOT.jar
  4. 此时curl会收到403响应,不会下载文件,同时Artifactory日志会记录拦截行为

内容的提问来源于stack exchange,提问作者Kim Chen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.25 15:25:02