You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

咨询:未登录直接访问链接时展示错误提示的实现方案

Solution to Restrict Direct Access to Your Portal

Alright, let's break down how to solve this. The core idea is to verify that visitors to www.xxx.com are coming from your authenticated admin portal, not accessing the URL directly. Here's a reliable approach:

Step 1: Modify the Upload Button to Pass a Valid Token

First, update your Upload button code to include a secure, time-limited token when redirecting. This token will prove the user is a logged-in admin coming from the right place.

Your button code would look something like this:

<ul>
  <li>
    <a href="https://www.xxx.com?access_token=<?php echo generate_admin_token(); ?>" id="upload-btn">Upload</a>
  </li>
</ul>

Then add this server-side function to generate the token (in your custom portal's code):

function generate_admin_token() {
    // Make sure this session variable exists after admin login
    $admin_id = $_SESSION['logged_in_admin_id'];
    $current_time = time();
    
    // Use a secret key (keep this safe, don't expose it publicly!)
    $secret_key = 'your_unique_secure_secret_key_here';
    
    // Create a hash combining admin ID, timestamp, and secret key
    $token = hash_hmac('sha256', $admin_id . '|' . $current_time, $secret_key);
    
    // Encode the token, admin ID, and timestamp to pass as a query parameter
    return urlencode($token . '|' . $admin_id . '|' . $current_time);
}

Step 2: Validate the Token on www.xxx.com

On the entry page of www.xxx.com (like index.php), add this validation logic before loading any page content:

<?php
$is_authorized = false;
$secret_key = 'your_unique_secure_secret_key_here'; // Same as the one in your custom portal

if (isset($_GET['access_token'])) {
    $token_parts = explode('|', urldecode($_GET['access_token']));
    
    // Ensure we have all 3 required parts: token, admin ID, timestamp
    if (count($token_parts) === 3) {
        list($received_token, $admin_id, $timestamp) = $token_parts;
        
        // Check if the token is still valid (e.g., expires after 5 minutes = 300 seconds)
        if (time() - $timestamp < 300) {
            // Re-generate the expected token to verify authenticity
            $expected_token = hash_hmac('sha256', $admin_id . '|' . $timestamp, $secret_key);
            
            // Use hash_equals to prevent timing attacks
            if (hash_equals($expected_token, $received_token)) {
                // Optional: Add an extra check by calling your custom portal's API to confirm the admin is still logged in
                // $admin_is_logged_in = call_custom_portal_api('verify_admin_session', $admin_id);
                // if ($admin_is_logged_in) {
                    $is_authorized = true;
                // }
            }
        }
    }
}

// If not authorized, show error and stop page load
if (!$is_authorized) {
    echo '<div style="max-width: 600px; margin: 50px auto; padding: 20px; border: 1px solid #dc3545; border-radius: 4px; background-color: #f8d7da; color: #721c24; text-align: center;">';
    echo '<h3>Access Denied</h3>';
    echo '<p>You do not have permission to access this page directly. Please log in to the admin portal and use the Upload button to access this page.</p>';
    echo '</div>';
    exit; // Prevent further content from loading
}

// If authorized, proceed with your normal page content
?>
<!-- Your regular www.xxx.com page HTML goes here -->

Key Notes for Security & Reliability

  • Keep the Secret Key Safe: Store it in a server-side config file, not in client-side code or version control.
  • Token Expiry: Adjust the 300-second window based on your needs—shorter is more secure.
  • Optional Extra Validation: If you want to be extra safe, add an API call to your custom portal to confirm the admin's session is still active.
  • Avoid Referer Checks: Don't rely solely on the Referer header, as it can be easily spoofed or blocked by browsers.

内容的提问来源于stack exchange,提问作者suresh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:49:19