You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP Web.Config配置:限制/files目录仅允许/School/来源请求访问

实现/files文件夹仅允许来自/School/目录请求访问的Web.Config配置方案

要限制/files下的文件仅能被来自/School/目录的请求访问,阻止用户直接通过文件链接访问的情况,你可以用以下两种Web.Config配置方案实现,匹配你提到的VB逻辑思路:

方案一:用IIS URL Rewrite模块(无需额外代码,推荐)

如果你的服务器安装了IIS URL Rewrite模块,直接在/files文件夹的web.config里添加以下规则,通过检查请求的Referer头过滤访问:

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
  <system.webServer>
    <rewrite>
      <rules>
        <rule name="Block Direct File Access" stopProcessing="true">
          <match url=".*" />
          <!-- 当Referer不包含/School/时触发拦截 -->
          <conditions>
            <add input="{HTTP_REFERER}" pattern="/School/" negate="true" />
          </conditions>
          <!-- 不符合条件的请求重定向到首页,也可以改成返回403禁止访问 -->
          <action type="Redirect" url="/index.aspx" redirectType="Found" />
          <!-- 若要直接拒绝访问,替换成下面的action:
          <action type="CustomResponse" statusCode="403" statusReason="Forbidden" statusDescription="Access Denied" />
          -->
        </rule>
      </rules>
    </rewrite>
  </system.webServer>
</configuration>

方案二:自定义HttpModule(基于你的VB代码逻辑)

如果需要更灵活的处理逻辑,可以编写自定义HttpModule,再在web.config中注册:

1. 编写VB HttpModule代码

创建FileAccessModule.vb类文件,代码如下:

Imports System.Web

Public Class FileAccessModule
    Implements IHttpModule

    Public Sub Dispose() Implements IHttpModule.Dispose
        ' 清理资源,无需额外操作
    End Sub

    Public Sub Init(context As HttpApplication) Implements IHttpModule.Init
        AddHandler context.BeginRequest, AddressOf OnBeginRequest
    End Sub

    Private Sub OnBeginRequest(sender As Object, e As EventArgs)
        Dim app = DirectCast(sender, HttpApplication)
        Dim referrer = app.Request.UrlReferrer

        ' 检查Referer是否存在且包含/School/,不符合则拦截
        If referrer Is Nothing OrElse Not referrer.ToString().Contains("/School/") Then
            app.Response.Redirect("/index.aspx")
            ' 也可以直接返回403:
            ' app.Response.StatusCode = 403
            ' app.Response.End()
        End If
    End Sub
End Class

2. 在/files的web.config中注册模块

<?xml version="1.0" encoding="UTF-8"?>
<configuration>
  <!-- 针对经典模式IIS -->
  <system.web>
    <httpModules>
      <add name="FileAccessModule" type="你的命名空间.FileAccessModule" />
    </httpModules>
  </system.web>
  <!-- 针对IIS 7+集成模式 -->
  <system.webServer>
    <modules>
      <add name="FileAccessModule" type="你的命名空间.FileAccessModule" preCondition="managedHandler" />
    </modules>
    <!-- 确保静态文件经过ASP.NET管道处理 -->
    <handlers>
      <add name="StaticFilesHandler" path="*" verb="*" type="System.Web.StaticFileHandler" preCondition="integratedMode" />
    </handlers>
  </system.webServer>
</configuration>

注意:把你的命名空间替换成这个类实际所在的命名空间。

重要提醒

  • Referer头可以被伪造,这种方式只能阻止普通用户直接访问,无法完全防范恶意请求。如果需要更高安全性,建议结合用户身份验证(比如Session、权限Cookie),确认用户确实有权访问/School/目录。
  • 如果/files文件夹已有现成的web.config,直接把上述配置合并到现有文件中即可。

内容的提问来源于stack exchange,提问作者NathanMedSchoolsHR

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 14:05:39