You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS S3:添加Referer策略后仍无法仅限自有网站访问存储桶资源

S3存储桶Referer策略配置后网站无法加载资源的排查方案

我参照AWS官方文档的Referer策略示例,为S3存储桶添加了仅允许自有网站访问资源的策略,结合原有账单报告相关策略后,网站仍无法加载桶内资源,相关策略如下:

原有存储桶策略

{
    "Version": "2008-10-17",
    "Id": "Policy1335892530063",
    "Statement": [
        {
            "Sid": "Stmt1335892150622",
            "Effect": "Allow",
            "Principal": {
                "Service": "billingreports.amazonaws.com"
            },
            "Action": [
                "s3:GetBucketAcl",
                "s3:GetBucketPolicy"
            ],
            "Resource": "arn:aws:s3:::bucket-name",
            "Condition": {
                "StringEquals": {
                    "aws:SourceArn": "arn:aws:cur:us-east-1:122xxxxxx328:definition/*",
                    "aws:SourceAccount": "122xxxxx328"
                }
            }
        },
        {
            "Sid": "Stmt1335892526596",
            "Effect": "Allow",
            "Principal": {
                "Service": "billingreports.amazonaws.com"
            },
            "Action": "s3:PutObject",
            "Resource": "arn:aws:s3:::bucket-name/*",
            "Condition": {
                "StringEquals": {
                    "aws:SourceArn": "arn:aws:cur:us-east-1:122xxxxx328:definition/*",
                    "aws:SourceAccount": "122xxxxx5328"
                }
            }
        }
    ]
}

新增自定义Referer策略

{
    "Sid": "Allow get requests originating from www.mywebsite.com and mywebsite.com.",
    "Effect": "Allow",
    "Principal": "*",
    "Action": [
        "s3:GetObject",
        "s3:GetObjectVersion"
    ],
    "Resource": "arn:aws:s3:::bucket-name/*",
    "Condition": {
        "StringLike": {
            "aws:Referer": [
                "https://www.mywebsite.com/*",
                "https://mywebsite.com/*"
            ]
        }
    }
}

最终组合后的存储桶策略

{
    "Version": "2008-10-17",
    "Id": "Policy1335892530063",
    "Statement": [
        {
            "Sid": "Stmt1335892150622",
            "Effect": "Allow",
            "Principal": {
                "Service": "billingreports.amazonaws.com"
            },
            "Action": [
                "s3:GetBucketAcl",
                "s3:GetBucketPolicy"
            ],
            "Resource": "arn:aws:s3:::bucket-name",
            "Condition": {
                "StringEquals": {
                    "aws:SourceArn": "arn:aws:cur:us-east-1:122xxxxxx328:definition/*",
                    "aws:SourceAccount": "122xxxxx328"
                }
            }
        },
        {
            "Sid": "Stmt1335892526596",
            "Effect": "Allow",
            "Principal": {
                "Service": "billingreports.amazonaws.com"
            },
            "Action": "s3:PutObject",
            "Resource": "arn:aws:s3:::bucket-name/*",
            "Condition": {
                "StringEquals": {
                    "aws:SourceArn": "arn:aws:cur:us-east-1:122xxxxx328:definition/*",
                    "aws:SourceAccount": "122xxxxx5328"
                }
            }
        },
        {
            "Sid": "Allow get requests originating from www.mywebsite.com and mywebsite.com.",
            "Effect": "Allow",
            "Principal": "*",
            "Action": [
                "s3:GetObject",
                "s3:GetObjectVersion"
            ],
            "Resource": "arn:aws:s3:::bucket-name/*",
            "Condition": {
                "StringLike": {
                    "aws:Referer": [
                        "https://www.mywebsite.com/*",
                        "https://mywebsite.com/*"
                    ]
                }
            }
        }
    ]
}

可能的原因及排查内容

  • 策略版本兼容性问题:当前组合策略使用2008-10-17版本,而官方示例采用更完善的2012-10-17版本,旧版本的条件判断逻辑可能存在差异。建议将策略版本统一为2012-10-17后重新测试。

  • Referer头匹配不完整:

    • 检查浏览器是否携带正确Referer头:隐私模式、浏览器插件或网站安全设置可能屏蔽/修改Referer;
    • 补充根域名匹配规则:当前策略仅匹配带路径的Referer(如https://www.mywebsite.com/page),但首页请求的Referer可能是https://www.mywebsite.com,需在aws:Referer列表中添加https://www.mywebsite.com和https://mywebsite.com;
    • 确认协议一致性:确保网站实际使用的HTTP/HTTPS协议与策略定义完全一致。
  • 对象级权限冲突:存储桶策略允许访问,但对象本身ACL如果设为私有,仍会拒绝请求。检查目标对象的ACL是否包含public-read权限,或确认桶策略是否覆盖了对象ACL。

  • 资源ARN拼写错误:验证策略中Resource字段的存储桶名称是否与实际桶名完全一致,避免拼写错误导致策略不生效。

  • 缓存影响:浏览器或CDN(如CloudFront)可能缓存了策略变更前的拒绝响应,需清除浏览器缓存或刷新CDN缓存后测试。

  • 其他权限限制:

    • 检查是否存在IAM用户/角色策略、组织级SCP或其他桶策略,对s3:GetObject动作设置了拒绝规则;
    • 通过CloudTrail日志查看具体请求拒绝原因,定位是条件不匹配还是权限不足。
  • 模拟请求验证:使用curl命令模拟带正确Referer的请求,验证策略是否生效:

    curl -H "Referer: https://www.mywebsite.com/" https://bucket-name.s3.amazonaws.com/your-object-key
    

内容的提问来源于stack exchange,提问作者AG_HIHI

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 22:25:18