如何使用Cloud DLP配置URL白名单?(Node.js客户端)
刚好做过类似的需求!要实现Cloud DLP识别URL但排除特定域名的URL,你可以通过给默认的URL InfoType添加**排除规则(ExclusionRule)**来搞定,下面是具体的Node.js实现方案:
核心思路
Cloud DLP允许我们为指定的InfoType添加规则集,其中的ExclusionRule可以定义“哪些内容不需要被检测”。这里我们可以用两种方式定义白名单:
- 用字典列表直接指定允许的域名,做部分匹配
- 用正则表达式精准匹配符合要求的URL
实现步骤&代码示例
1. 先安装依赖
确保你已经安装了Cloud DLP的Node.js客户端库:
npm install @google-cloud/dlp
2. 完整代码实现
下面的代码会初始化DLP客户端,配置URL检测规则并添加白名单排除逻辑:
const { DlpServiceClient } = require('@google-cloud/dlp'); // 封装检测函数 async function inspectContentWithWhitelistedURLs() { // 初始化DLP客户端 const dlpClient = new DlpServiceClient(); // 替换为你的GCP项目ID const projectId = 'your-gcp-project-id'; // 待检测的文本内容 const targetText = ` 这是测试内容: 允许的URL:https://www.google.com/search?q=test,https://mail.yahoo.com/inbox 需要被识别的URL:https://fake-phish-site.com/steal-data `; // 定义白名单域名 const allowedDomains = ['google.com', 'yahoo.com']; // 构建排除规则:包含白名单域名的URL将被排除检测 const urlExclusionRule = { // 使用字典匹配,部分匹配即可生效 dictionary: { wordList: { words: allowedDomains, }, }, matchingType: 'MATCHING_TYPE_PARTIAL_MATCH', }; // 构建检测配置 const inspectConfig = { // 指定要检测的InfoType:默认的URL类型 infoTypes: [{ name: 'URL' }], // 为URL类型添加规则集 ruleSet: [ { infoTypes: [{ name: 'URL' }], rules: [{ exclusionRule: urlExclusionRule }], }, ], // 开启返回匹配到的文本片段,方便调试 includeQuote: true, }; // 构建请求参数 const request = { parent: `projects/${projectId}/locations/global`, inspectConfig, item: { value: targetText }, }; // 发送检测请求并处理结果 try { const [response] = await dlpClient.inspectContent(request); console.log('=== 检测结果 ==='); if (response.result.findings.length === 0) { console.log('未识别到需要拦截的URL'); } else { response.result.findings.forEach(finding => { console.log(`识别到敏感类型: ${finding.infoType.name}`); console.log(`匹配内容: ${finding.quote}`); console.log(`置信度: ${finding.likelihood}`); }); } } catch (error) { console.error('检测过程出错:', error); } } // 执行检测 inspectContentWithWhitelistedURLs();
进阶:精准匹配URL
如果需要更严格的匹配(比如只允许以google.com/yahoo.com结尾的域名,不允许子域名或者其他变种),可以把排除规则换成正则表达式:
const urlExclusionRule = { regex: { // 正则匹配http/https开头,域名以google.com或yahoo.com结尾的URL pattern: 'https?://[^/]*\\.(google|yahoo)\\.com(/.*)?$', }, matchingType: 'MATCHING_TYPE_FULL_MATCH', };
这样就能精准控制哪些URL会被排除在检测之外啦!
内容的提问来源于stack exchange,提问作者FlutterFirebase
相关产品推荐
相关产品推荐

