You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Cloud存储跨域配置不生效:无法限制Bucket对象仅指定域名访问

Why Your CORS Rules Aren't Restricting Access to Your Public GCS Object

Hey there, let's break down what's going on here and fix this for you. First off, a critical misunderstanding to clear up: CORS rules don't control object access permissions in Google Cloud Storage. They only dictate how browsers handle cross-origin requests to the resource. Your object is currently set to public, which means anyone can access it directly via its URL—regardless of your CORS configuration. That's exactly why your setup isn't working as expected.

Here's How to Fix It

To restrict access so only https://example.com can load the object, you need two key steps: revoke the object's public access, then implement a method to grant access exclusively to your website.

Step 1: Make the Object Private

First, strip away the public permissions that are letting anyone access your file:

  • Head to the Google Cloud Console, navigate to your cros-test bucket.
  • Find the 480_intro%20v2_2.mp4 object, click the three-dot menu, and select Edit permissions.
  • Delete any permission entries that grant access to allUsers or allAuthenticatedUsers—these are what make the object publicly accessible.

Step 2: Choose a Method to Restrict Access to example.com

You have two reliable, production-ready options here:

Option 1: Use Signed URLs (Best for Dynamic Content)

Signed URLs let you generate time-limited, authorized links to your private objects. Your website's backend can create these URLs on-demand, and only requests using a valid signed URL will be allowed to access the object:

  • Use the Google Cloud SDK (for your language of choice) in your backend code to generate a signed URL for the object. You can set an expiration window (e.g., 1 hour) to limit how long the link remains valid.
  • Replace the public GCS URL in your example.com pages with this signed URL.
  • Your existing CORS rules already allow example.com to make cross-origin requests to these signed URLs, so browsers will load the content without issues.

Option 2: Use Cloud CDN with Referer Filtering (Best for Static Content)

If your content is static, Cloud CDN lets you enforce referer-based access control to block unauthorized requests:

  1. Create a Cloud CDN distribution using your private GCS bucket as the origin.
  2. In the CDN's security settings, add a Referer restriction that only allows requests from https://example.com/*.
  3. Update your example.com pages to use the CDN URL instead of the direct GCS URL.
    This setup ensures only requests coming from your website (with a valid example.com referer header) can access the content. Direct requests to the CDN or GCS URL will be blocked entirely.

Why Your Original Setup Failed

When your object is public, GCS allows any request to access it—whether it's from a browser address bar, a curl command, or another website. CORS rules only kick in when a browser makes a cross-origin request (like example.com loading the object in a <video> tag). They don't prevent direct access to the public URL because those requests aren't cross-origin, so the browser doesn't perform a CORS preflight check.

内容的提问来源于stack exchange,提问作者jared zek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 09:28:42