You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何禁止直接访问服务器用户上传ZIP文件?此前提问未获答复重询

Hey there! Let me walk you through the best solutions for this exact scenario—since you mentioned you tried .htaccess already, I’ll start with the polished Apache config, plus cover Nginx if you’re on that stack, and even a more robust fallback for edge cases.

最优实现方案

Apache(.htaccess)配置

The core idea here is checking the Referer HTTP header: when a user clicks a link from your site, their browser sends this header with your domain; if they type the URL directly, the header is either missing or not from your site.

Here’s the solid .htaccess config to enforce this:

RewriteEngine On

# Block direct access to ZIP files unless the request comes from your domain
RewriteCond %{HTTP_REFERER} !^https://www\.example\.com/ [NC]
RewriteRule \.zip$ - [F,L]

Let’s break this down:

  • RewriteCond %{HTTP_REFERER} !^https://www\.example\.com/ [NC]: Checks if the referrer isn’t your domain (NC makes it case-insensitive)
  • RewriteRule \.zip$ - [F,L]: Matches any ZIP file, returns a 403 Forbidden (F) and stops processing further rules (L)

If you want to be extra strict (block even requests with no referrer), adjust it to:

RewriteEngine On
RewriteCond %{HTTP_REFERER} !^https://www\.example\.com/.*$ [NC]
RewriteRule \.zip$ - [R=403,L]

Nginx Configuration

If you’re using Nginx instead of Apache, here’s the equivalent rule:

location ~* \.zip$ {
    # List your allowed domains here (include both www and non-www if needed)
    valid_referers www.example.com example.com;
    if ($invalid_referer) {
        return 403;
    }
}

The valid_referers directive defines which referrers are allowed; any request outside this list triggers $invalid_referer, which we use to return a 403.

Edge Case: Browsers with Disabled Referrers

A heads-up: some users have privacy settings that block sending the Referer header. In those cases, the above rules might incorrectly block legitimate users who clicked your link. For a more reliable (but slightly more involved) solution, use signed temporary URLs:

  1. Generate signed links on your site: Create URLs that include an expiration timestamp and a cryptographic signature tied to your secret key. Here’s a quick PHP example:
$file = 'uploads/1.zip';
$expires = time() + 3600; // Link expires in 1 hour
$secret = 'your-strong-secret-key'; // Keep this safe!

// Create a unique signature for the file and expiration time
$signature = hash_hmac('sha256', $file . $expires, $secret);

// Build the signed URL
$signedUrl = "https://www.example.com/$file?expires=$expires&signature=$signature";
  1. Validate the signature on the server: Add a script (or server config) to check if the signature is valid and the link hasn’t expired before allowing access. For example, a PHP validation script:
$requestedFile = $_SERVER['REQUEST_URI'];
$expires = $_GET['expires'] ?? 0;
$providedSignature = $_GET['signature'] ?? '';
$secret = 'your-strong-secret-key';

// Check if the link is expired or signature is invalid
if ($expires < time() || !hash_equals(hash_hmac('sha256', $requestedFile . $expires, $secret), $providedSignature)) {
    http_response_code(403);
    exit('Forbidden: Invalid or expired link');
}

// If valid, serve the file
readfile($requestedFile);

This method is more secure and avoids relying on the Referer header entirely.

内容的提问来源于stack exchange,提问作者blogo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:49:44