You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何借助Cloud DLP Node.js客户端库配置URL白名单?

在Cloud DLP中为URL infoType设置白名单(Node.js客户端)

刚好做过类似的需求!要实现Cloud DLP识别URL但白名单放行google.com和yahoo.com的URL,你可以通过自定义规则里的排除规则来搞定——既保留默认的URL识别能力,又让指定域名的URL跳过检测。

核心思路

Cloud DLP的规则系统允许我们针对特定infoType添加排除条件:

  1. 启用默认的URL infoType来识别所有URL
  2. 给URL类型添加一条排除规则,匹配包含google.com或yahoo.com的URL,这类URL就不会被标记为敏感数据

Node.js代码实现

直接上可运行的代码示例,记得替换成你的项目ID:

const DLP = require('@google-cloud/dlp');
const dlp = new DLP.DlpServiceClient();

async function inspectContentWithWhitelist() {
  // 待检测的文本内容
  const contentItem = {
    value: '请访问这些链接:https://example.com、https://google.com、https://mail.yahoo.com、https://unknown.org'
  };

  // 定义白名单排除规则:放行google.com和yahoo.com相关的URL
  const urlWhitelistRule = {
    // 针对URL这个infoType生效
    infoTypes: [{ name: 'URL' }],
    // 部分匹配即可(不需要完全一致)
    matchingType: 'MATCHING_TYPE_PARTIAL_MATCH',
    // 用正则匹配目标域名,可根据需求调整
    regex: {
      pattern: 'https?://(www\\.)?(google\\.com|yahoo\\.com)(/.*)?'
    }
  };

  // 构建检测配置
  const inspectConfig = {
    // 启用默认的URL识别
    infoTypes: [{ name: 'URL' }],
    // 添加规则集,将排除规则绑定到URL类型上
    ruleSet: [
      {
        infoTypes: [{ name: 'URL' }],
        rules: [
          {
            exclusionRule: urlWhitelistRule
          }
        ]
      }
    ]
  };

  // 组装请求参数
  const request = {
    parent: dlp.projectPath('YOUR_PROJECT_ID'), // 替换成你的GCP项目ID
    inspectConfig: inspectConfig,
    item: contentItem
  };

  // 发送检测请求并处理结果
  try {
    const [response] = await dlp.inspectContent(request);
    const findings = response.result.findings;

    if (findings.length > 0) {
      console.log('被标记的敏感URL:');
      findings.forEach(finding => {
        console.log(`类型: ${finding.infoType.name}, 内容: ${finding.quote}`);
      });
    } else {
      console.log('未发现需要标记的敏感URL');
    }
  } catch (err) {
    console.error('检测出错:', err);
  }
}

// 执行检测函数
inspectContentWithWhitelist();

关键细节说明

  • 正则表达式:示例里的正则会匹配http/https开头、带或不带www前缀、以及google.com/yahoo.com下的所有子路径(比如https://mail.yahoo.com/inbox),你可以根据实际需求修改,比如要不要包含子域名、要不要限制路径等。
  • 匹配类型:用MATCHING_TYPE_PARTIAL_MATCH意味着只要URL里包含匹配的域名部分就会被放行,不需要整个URL完全匹配正则。
  • 规则绑定:通过ruleSet把排除规则和URL infoType绑定,确保规则只对URL识别生效,不会影响其他infoType的检测。

测试验证

运行代码后,你会发现https://example.com和https://unknown.org会被标记为敏感URL,而https://google.com和https://mail.yahoo.com会被白名单放行,不会出现在结果里。

内容的提问来源于stack exchange,提问作者FlutterFirebase

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:54:46