You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何禁用Spring Cloud Config Server的/decrypt端点以保障加密安全?

禁用Spring Cloud Config Server的/decrypt端点

问题背景

当前Spring Cloud Config Server的/decrypt端点处于启用状态,任何可访问该端点的用户都能解密加密内容,导致加密机制失去安全性,存在敏感信息泄露风险。相关操作示例如下:

  • 加密请求:
    • URL: http://localhost:23000/encrypt
    • 请求体: hello
    • 响应: 8c27f45094636aee57e2e132f
  • 解密操作(注:原提问中URL误写为/encrypt,实际应为/decrypt):
    • URL: http://localhost:23000/decrypt
    • 请求体: 8c27f45094636aee57e2e132f
    • 响应: hello

以下是几种禁用/decrypt端点的可行方案:

解决方案

方法1:通过配置直接关闭端点

利用Spring Cloud Config的原生配置,可快速禁用/decrypt端点,支持properties或yml两种配置格式:

properties配置示例:

# 单独禁用decrypt端点
management.endpoint.decrypt.enabled=false
# 从web暴露的端点列表中排除decrypt
management.endpoints.web.exposure.exclude=decrypt

# 若需全局关闭加密解密功能,可添加以下配置
# spring.cloud.config.server.encrypt.enabled=false

yml配置示例:

management:
  endpoint:
    decrypt:
      enabled: false # 禁用decrypt端点
  endpoints:
    web:
      exposure:
        exclude: decrypt # 不在web端暴露该端点

# 全局关闭加密解密功能的配置(可选)
# spring:
#   cloud:
#     config:
#       server:
#         encrypt:
#           enabled: false

方法2:通过Spring Security拦截访问

如果需要更灵活的权限控制(比如仅拒绝未授权访问,而非完全禁用),可以通过Spring Security拦截/decrypt端点的所有请求:

import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.web.SecurityFilterChain;

@Configuration
public class ConfigSecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http.authorizeHttpRequests(auth -> auth
                .requestMatchers("/decrypt").denyAll() // 拒绝所有/decrypt请求
                .anyRequest().permitAll() // 其他端点保持正常访问,可按需调整
        );
        return http.build();
    }
}

方法3:自定义配置排除解密端点

通过自定义配置类,仅注册加密端点、不注册解密端点,从根源上禁用/decrypt:

import org.springframework.boot.actuate.autoconfigure.endpoint.condition.ConditionalOnEnabledEndpoint;
import org.springframework.boot.autoconfigure.condition.ConditionalOnMissingBean;
import org.springframework.cloud.config.server.encrypt.EncryptEndpoint;
import org.springframework.context.annotation.Bean;
import org.springframework.context.annotation.Configuration;
import org.springframework.context.annotation.Import;

@Configuration
@Import(EncryptEndpoint.class) // 仅导入加密端点
public class CustomEncryptionConfig {

    @Bean
    @ConditionalOnMissingBean
    @ConditionalOnEnabledEndpoint
    public EncryptEndpoint encryptEndpoint() {
        return new EncryptEndpoint();
    }

    // 不定义DecryptEndpoint的Bean,即可阻止该端点注册
}

内容的提问来源于stack exchange,提问作者Charan257

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 08:40:32