网络安全:Spring Boot Actuator的env/info端点泄露MongoDB连接串问题咨询
可行解决方案汇总
以下方案均不需要调整MongoDB驱动的uri配置方式,可直接实现敏感属性隐藏:
方案1:使用Actuator内置脱敏配置
Spring Boot Actuator原生支持自定义需要脱敏的属性key,配置后env、info等端点会自动将匹配的属性值替换为******。
配置示例(application.properties):
# 配置env端点要脱敏的属性 management.endpoint.env.keys-to-sanitize=spring.data.mongodb.uri,password,secret,token,key # 配置info端点要脱敏的属性 management.endpoint.info.keys-to-sanitize=spring.data.mongodb.uri,password,secret,token,key
配置示例(application.yml):
management: endpoint: env: keys-to-sanitize: spring.data.mongodb.uri,password,secret,token,key info: keys-to-sanitize: spring.data.mongodb.uri,password,secret,token,key
该方案配置简单,满足绝大多数场景的隐藏需求。
方案2:自定义脱敏规则实现灵活处理
如果需要保留uri中非敏感部分(如仅隐藏密码段),可自定义SanitizingFunction实现:
import org.springframework.boot.actuate.endpoint.SanitizableData; import org.springframework.boot.actuate.endpoint.SanitizingFunction; import org.springframework.stereotype.Component; import java.util.regex.Matcher; import java.util.regex.Pattern; @Component public class MongoUriSanitizer implements SanitizingFunction { private static final Pattern MONGO_URI_PATTERN = Pattern.compile("mongodb://([^:]+):([^@]+)@(.*)"); @Override public SanitizableData apply(SanitizableData data) { if (!"spring.data.mongodb.uri".equals(data.getKey()) || data.getValue() == null) { return data; } String uri = data.getValue().toString(); Matcher matcher = MONGO_URI_PATTERN.matcher(uri); if (matcher.matches()) { // 仅替换密码部分为***,也可根据需求直接替换整个uri为*** String safeUri = uri.replace(matcher.group(2), "***"); return data.withValue(safeUri); } return data; } }
该类注册为Bean后会自动生效,所有Actuator端点返回的MongoDB uri都会按自定义规则处理。
方案3:端点访问管控
如果不需要对外暴露env、info端点,可直接关闭公网暴露:
management.endpoints.web.exposure.exclude=env,info
如果需要内部使用,可结合Spring Security给Actuator端点配置访问权限,仅授权账号可访问,从访问层面避免信息泄露。
内容的提问来源于stack exchange,提问作者SkyBlackHawk
相关产品推荐
相关产品推荐

