You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

为htaccess的PDF重定向URL追加查询字符串,拦截PDF直接访问

Solution: Block Direct PDF Access While Keeping Key-Based Downloads

Hey there! Your core issue makes total sense—relying on "secret" URLs for PDFs is risky because they can get shared or scraped. Redirects are part of the solution, but we need to pair them with access validation to lock down direct access completely. Let’s break down actionable steps for different server setups, plus a more secure approach to your download flow:

1. Server-Level Interception (Most Efficient)

This method intercepts all PDF requests before they reach the file, forcing them through your key validation logic first.

For Apache Users

Add this to your .htaccess file in the directory where PDFs are stored:

RewriteEngine On
# Route all PDF requests to your validation script
RewriteRule ^(.*\.pdf)$ /validate-key.php?file=$1 [L]

Then create validate-key.php to handle the check:

<?php
session_start();

// Check if the user has a valid download key (adjust this to match your key system)
if (!isset($_SESSION['valid_download_key']) || !$_SESSION['valid_download_key']) {
    // Redirect to your key request page if validation fails
    header("Location: /request-key-page.php");
    exit;
}

// Sanitize the file path to prevent directory traversal attacks
$allowed_pdf_dir = realpath('/path/to/your/secure/pdf/folder/');
$requested_file = basename($_GET['file']);
$full_file_path = $allowed_pdf_dir . '/' . $requested_file;

// Verify the file exists and is within the allowed directory
if (!file_exists($full_file_path) || strpos(realpath($full_file_path), $allowed_pdf_dir) !== 0) {
    header("HTTP/1.1 403 Forbidden");
    echo "Access denied: Invalid file request.";
    exit;
}

// If all checks pass, serve the PDF
header('Content-Type: application/pdf');
header('Content-Disposition: inline; filename="' . $requested_file . '"');
header('Content-Length: ' . filesize($full_file_path));
readfile($full_file_path);
exit;

For Nginx Users

Add this to your Nginx server block:

location ~* \.pdf$ {
    # Forward PDF requests to your validation script
    rewrite ^ /validate-key.php?file=$uri last;
}

The validate-key.php logic remains the same as above—just make sure to adjust the file path checks since Nginx’s $uri includes the full path.

2. Boost Security: Store PDFs Outside the Web Root

For an extra layer of protection, move all your PDF files to a directory not accessible via direct web requests (e.g., /var/app/private-pdfs/ instead of /var/www/html/). This means even if someone bypasses your server rules, they can’t reach the files at all. Your validation script will still be able to read the files from this private directory and serve them to authorized users.

3. Fixing Your Redirect Approach

If you want to stick with redirects, the key mistake is probably not intercepting the PDF request first. Instead of redirecting after someone accesses the PDF, intercept the request before it hits the file:

  • When a user tries to access a PDF URL directly, they’re sent to your validation script.
  • If they have a valid key, the script serves the PDF (no redirect needed).
  • If not, redirect them to your key request page.

This way, direct PDF URLs never resolve to the actual file—they always go through your check.

Testing on Your Demo Subdomain

Start small to validate:

  1. Upload a test PDF and set up the server rule/validation script.
  2. Try accessing the PDF URL directly—you should be sent to the key request page.
  3. Complete the key request flow (set a valid key in the session, for example) and revisit the PDF URL—you should see the file load.
  4. Test for directory traversal by trying URLs like ../secret.pdf to ensure your script blocks invalid requests.

内容的提问来源于stack exchange,提问作者Alisha Narvaez

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:47:43