You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Amazon S3实现类似Vimeo的域名级隐私视频嵌入功能?

Got it, let's walk through how to set up domain-level embedding restrictions for your private Camtasia interactive videos on Amazon S3—mirroring Vimeo's domain privacy feature. Here's a practical, step-by-step solution:

Core Approach

S3 doesn't have a built-in "allow specific domains to embed" toggle like Vimeo, but we can combine CloudFront (for edge control) + Origin Access Control (to keep S3 files private) + CloudFront Functions (to validate referrers) to achieve the same effect. Alternatively, for simpler use cases, you can use pre-signed URLs with S3 bucket policies, but CloudFront is better for long-term, scalable embedding.

Step-by-Step Implementation

1. Set Up CloudFront with Origin Access Control (OAC)

First, route all video traffic through CloudFront to enforce restrictions and keep your S3 bucket private:

  • Create a new CloudFront distribution, selecting your S3 bucket as the origin.
  • Use Origin Access Control (OAC) instead of the older OAI: this ensures only CloudFront can access your S3 files, so you don't need to make any S3 objects public.
  • Configure the default cache behavior to allow GET and HEAD requests (standard for media files).

2. Create a CloudFront Function to Validate Referrers

This function will check if the request comes from your allowed domain(s) by inspecting the Referer header:

  • Go to the CloudFront Functions console, create a new function with this code (replace allowedDomains with your actual domains):
    function handler(event) {
        const request = event.request;
        const allowedDomains = ["yourdomain.com", "blog.yourdomain.com"]; // Add your permitted domains
        const referer = request.headers.referer ? request.headers.referer.value : "";
    
        // Check if the referer matches any allowed domain
        const isAllowed = allowedDomains.some(domain => referer.includes(domain));
    
        // Block requests without a valid referer
        if (!referer || !isAllowed) {
            return {
                statusCode: 403,
                statusDescription: "Forbidden - Embedding restricted to authorized domains"
            };
        }
    
        // Allow valid requests to proceed to S3
        return request;
    }
    
  • Publish the function, then associate it with your CloudFront distribution's default cache behavior (set the event type to Viewer Request).

3. Configure S3 CORS for Cross-Domain Embedding

Since your video will be loaded via iframe from your domain, you need to allow cross-origin requests in S3:

  • Go to your S3 bucket's Permissions tab, edit the CORS configuration, and paste this (replace with your domains):
    <?xml version="1.0" encoding="UTF-8"?>
    <CORSConfiguration xmlns="http://s3.amazonaws.com/doc/2006-03-01/">
        <CORSRule>
            <AllowedOrigin>https://yourdomain.com</AllowedOrigin>
            <AllowedOrigin>https://blog.yourdomain.com</AllowedOrigin>
            <AllowedMethod>GET</AllowedMethod>
            <AllowedMethod>HEAD</AllowedMethod>
            <AllowedHeader>*</AllowedHeader>
            <ExposeHeader>Content-Length</ExposeHeader>
            <ExposeHeader>Content-Type</ExposeHeader>
        </CORSRule>
    </CORSConfiguration>
    

This tells S3 to allow requests from your domain when embedded in an iframe.

4. (Alternative) Use Pre-Signed URLs with S3 Bucket Policies

If you don't want to use CloudFront, you can use pre-signed URLs (temporary access links) combined with a bucket policy that checks the Referer header:

  • Create an S3 bucket policy like this (replace bucket name and domains):
    {
        "Version": "2012-10-17",
        "Statement": [
            {
                "Effect": "Allow",
                "Principal": "*",
                "Action": "s3:GetObject",
                "Resource": "arn:aws:s3:::your-bucket-name/*",
                "Condition": {
                    "StringLike": {
                        "aws:Referer": [
                            "https://yourdomain.com/*",
                            "https://blog.yourdomain.com/*"
                        ]
                    }
                }
            }
        ]
    }
    
  • Generate pre-signed URLs for your videos (using AWS CLI, SDK, or S3 console). These URLs will only work when accessed from your allowed domains. Note: Pre-signed URLs expire after a set time, so this is better for temporary embeds rather than permanent ones.

5. Test the Embedding

  • On your authorized domain, add an iframe pointing to your CloudFront URL (or pre-signed URL):
    <iframe src="https://your-cloudfront-id.cloudfront.net/path/to/your/camtasia-video.mp4" 
            width="1280" 
            height="720" 
            frameborder="0" 
            allowfullscreen></iframe>
    
  • Try embedding the same URL on a different domain: you should get a 403 Forbidden error, confirming the restriction works.
Key Notes
  • CloudFront is Preferred: It's scalable, low-latency, and the function-based validation is robust for long-term use.
  • Referer Limitations: While Referer validation works for most embedding scenarios, it's possible to spoof the header. For stricter security, combine this with CloudFront Signed Cookies/URLs (which require a signature to access content).
  • Keep S3 Files Private: Never set your S3 objects to public read—OAC ensures CloudFront is the only entity with access to your bucket.

内容的提问来源于stack exchange,提问作者makesz1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 06:52:37