【问题标题】:Security for downloading .bin files下载 .bin 文件的安全性
【发布时间】:2020-07-14 08:33:21
【问题描述】:

我创建了 .bin 文件下载功能。我所有的 .bin 文件都存储在“storage/app/files”文件夹中。视图模板中的用户按下下载按钮,这会吸引处理所有下载功能的控制器(检查用户是否已登录,文件是否存在于“storage/app/files”文件夹中)。我的问题是,将所有重要文件存储到此文件夹是否安全?我需要写一个 .htaccess 文件吗?

【问题讨论】:

    标签: laravel file security filesystems downloadfile


    【解决方案1】:

    只有您的public 文件夹(带有index.php)应该可以访问,这是根目录(有时该目录被命名为public_html)。

    除此之外的任何目录(如 storage/app/vendor 等)都应无法通过 URL 访问。

    如果你想控制你的文件,“一切”必须首先通过index.php。 因此,为了提供像storage/app/files/xxx.png 这样的资产,您应该使用控制器。该代码可能如下所示:

    // SomeController.php
    public function showAvatar(Request $request)
    {
        // Select the `local` disk as defined in `config/filesystems.php`.
        $disk = Storage::disk('local');
        return response()->file($disk->path('files/xxx.png'));
    }
    

    然后您可以使用中间件或其他代码对这些文件提供限制。

    【讨论】:

    • 但是我做对了吗,为了安全地存储我需要将它们放置到“存储”文件夹中的所有文件?
    • 是的,这是一个解决方案,只要您正确配置了网络服务器,这样您就无法调用类似example.com/storage/app/files/image.png 的东西。
    猜你喜欢
    • 2012-06-05
    • 2011-04-22
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2012-11-11
    • 2018-08-16
    相关资源
    最近更新 更多