咨询:未登录直接访问链接时展示错误提示的实现方案
Solution to Restrict Direct Access to Your Portal
Alright, let's break down how to solve this. The core idea is to verify that visitors to www.xxx.com are coming from your authenticated admin portal, not accessing the URL directly. Here's a reliable approach:
Step 1: Modify the Upload Button to Pass a Valid Token
First, update your Upload button code to include a secure, time-limited token when redirecting. This token will prove the user is a logged-in admin coming from the right place.
Your button code would look something like this:
<ul> <li> <a href="https://www.xxx.com?access_token=<?php echo generate_admin_token(); ?>" id="upload-btn">Upload</a> </li> </ul>
Then add this server-side function to generate the token (in your custom portal's code):
function generate_admin_token() { // Make sure this session variable exists after admin login $admin_id = $_SESSION['logged_in_admin_id']; $current_time = time(); // Use a secret key (keep this safe, don't expose it publicly!) $secret_key = 'your_unique_secure_secret_key_here'; // Create a hash combining admin ID, timestamp, and secret key $token = hash_hmac('sha256', $admin_id . '|' . $current_time, $secret_key); // Encode the token, admin ID, and timestamp to pass as a query parameter return urlencode($token . '|' . $admin_id . '|' . $current_time); }
Step 2: Validate the Token on www.xxx.com
On the entry page of www.xxx.com (like index.php), add this validation logic before loading any page content:
<?php $is_authorized = false; $secret_key = 'your_unique_secure_secret_key_here'; // Same as the one in your custom portal if (isset($_GET['access_token'])) { $token_parts = explode('|', urldecode($_GET['access_token'])); // Ensure we have all 3 required parts: token, admin ID, timestamp if (count($token_parts) === 3) { list($received_token, $admin_id, $timestamp) = $token_parts; // Check if the token is still valid (e.g., expires after 5 minutes = 300 seconds) if (time() - $timestamp < 300) { // Re-generate the expected token to verify authenticity $expected_token = hash_hmac('sha256', $admin_id . '|' . $timestamp, $secret_key); // Use hash_equals to prevent timing attacks if (hash_equals($expected_token, $received_token)) { // Optional: Add an extra check by calling your custom portal's API to confirm the admin is still logged in // $admin_is_logged_in = call_custom_portal_api('verify_admin_session', $admin_id); // if ($admin_is_logged_in) { $is_authorized = true; // } } } } } // If not authorized, show error and stop page load if (!$is_authorized) { echo '<div style="max-width: 600px; margin: 50px auto; padding: 20px; border: 1px solid #dc3545; border-radius: 4px; background-color: #f8d7da; color: #721c24; text-align: center;">'; echo '<h3>Access Denied</h3>'; echo '<p>You do not have permission to access this page directly. Please log in to the admin portal and use the Upload button to access this page.</p>'; echo '</div>'; exit; // Prevent further content from loading } // If authorized, proceed with your normal page content ?> <!-- Your regular www.xxx.com page HTML goes here -->
Key Notes for Security & Reliability
- Keep the Secret Key Safe: Store it in a server-side config file, not in client-side code or version control.
- Token Expiry: Adjust the 300-second window based on your needs—shorter is more secure.
- Optional Extra Validation: If you want to be extra safe, add an API call to your custom portal to confirm the admin's session is still active.
- Avoid Referer Checks: Don't rely solely on the
Refererheader, as it can be easily spoofed or blocked by browsers.
内容的提问来源于stack exchange,提问作者suresh
相关产品推荐
相关产品推荐

