You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure门户阻止Azure App Services的特定MIME类型(.inc)文件?

阻止Azure App Service提供.inc文件的方法

Azure门户直接操作说明

目前Azure门户没有专门的界面用于禁用特定文件类型的MIME映射或直接阻止文件访问,因此需要通过配置文件来实现需求。

通过web.config实现(推荐方案)

可以通过修改站点根目录下的web.config文件,使用IIS的请求过滤规则直接禁止.inc文件的访问,具体配置如下:

<configuration>
  <system.webServer>
    <security>
      <requestFiltering>
        <fileExtensions>
          <!-- 将.inc文件设置为不允许访问 -->
          <add fileExtension=".inc" allowed="false" />
        </fileExtensions>
      </requestFiltering>
    </security>
  </system.webServer>
</configuration>

配置说明

  • 该配置通过IIS的requestFiltering模块直接拦截所有针对.inc文件的请求,客户端会收到404 Not Found或403 Forbidden响应,彻底阻止.inc文件被提供。
  • 如果站点原本存在.inc文件的MIME类型映射,可搭配移除映射的配置实现双重保障:
<configuration>
  <system.webServer>
    <staticContent>
      <remove fileExtension=".inc" />
    </staticContent>
    <security>
      <requestFiltering>
        <fileExtensions>
          <add fileExtension=".inc" allowed="false" />
        </fileExtensions>
      </requestFiltering>
    </security>
  </system.webServer>
</configuration>

操作步骤

  1. 登录Azure门户,进入目标App Service的「高级工具」(Kudu)。
  2. 在Kudu的「调试控制台」中选择「CMD」或「PowerShell」,导航到站点的wwwroot目录。
  3. 编辑或创建web.config文件,添加上述配置代码。
  4. 保存文件后配置立即生效,无需重启站点。

内容的提问来源于stack exchange,提问作者John Cherry

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.28 14:47:30