Google Cloud存储跨域配置不生效:无法限制Bucket对象仅指定域名访问
Hey there, let's break down what's going on here and fix this for you. First off, a critical misunderstanding to clear up: CORS rules don't control object access permissions in Google Cloud Storage. They only dictate how browsers handle cross-origin requests to the resource. Your object is currently set to public, which means anyone can access it directly via its URL—regardless of your CORS configuration. That's exactly why your setup isn't working as expected.
Here's How to Fix It
To restrict access so only https://example.com can load the object, you need two key steps: revoke the object's public access, then implement a method to grant access exclusively to your website.
Step 1: Make the Object Private
First, strip away the public permissions that are letting anyone access your file:
- Head to the Google Cloud Console, navigate to your
cros-testbucket. - Find the
480_intro%20v2_2.mp4object, click the three-dot menu, and select Edit permissions. - Delete any permission entries that grant access to
allUsersorallAuthenticatedUsers—these are what make the object publicly accessible.
Step 2: Choose a Method to Restrict Access to example.com
You have two reliable, production-ready options here:
Option 1: Use Signed URLs (Best for Dynamic Content)
Signed URLs let you generate time-limited, authorized links to your private objects. Your website's backend can create these URLs on-demand, and only requests using a valid signed URL will be allowed to access the object:
- Use the Google Cloud SDK (for your language of choice) in your backend code to generate a signed URL for the object. You can set an expiration window (e.g., 1 hour) to limit how long the link remains valid.
- Replace the public GCS URL in your
example.compages with this signed URL. - Your existing CORS rules already allow
example.comto make cross-origin requests to these signed URLs, so browsers will load the content without issues.
Option 2: Use Cloud CDN with Referer Filtering (Best for Static Content)
If your content is static, Cloud CDN lets you enforce referer-based access control to block unauthorized requests:
- Create a Cloud CDN distribution using your private GCS bucket as the origin.
- In the CDN's security settings, add a Referer restriction that only allows requests from
https://example.com/*. - Update your
example.compages to use the CDN URL instead of the direct GCS URL.
This setup ensures only requests coming from your website (with a validexample.comreferer header) can access the content. Direct requests to the CDN or GCS URL will be blocked entirely.
Why Your Original Setup Failed
When your object is public, GCS allows any request to access it—whether it's from a browser address bar, a curl command, or another website. CORS rules only kick in when a browser makes a cross-origin request (like example.com loading the object in a <video> tag). They don't prevent direct access to the public URL because those requests aren't cross-origin, so the browser doesn't perform a CORS preflight check.
内容的提问来源于stack exchange,提问作者jared zek

