写入对象存储时下发对象级 ACL,修掉发行包可匿名直取
Project CI / AI game creator shell Rust crates (push) Successful in 1m30s
Project CI / AI game creator shell Rust smoke (push) Successful in 1m52s
Project CI / Backend tests (push) Successful in 4m55s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 8m4s
Project CI / Native shell tests (push) Successful in 6m20s
Project CI / Frontend tests (push) Successful in 2m11s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 9m6s
Project CI / AI game creator shell web tests (push) Successful in 1m40s
Project CI / Repository checks (push) Successful in 2m12s

- platform-oss 的内部 PUT 与分片追加显式下发 x-oss-object-acl(Private 为 private、Public 为 public-read),OssAppendInternalObjectRequest 增加 access 字段
- 直传 policy 增加 x-oss-object-acl 条件,表单字段与 shared-contracts 的 DirectUploadTicketFormFields 同步新增并透传到 ticket 响应
- 媒体链路 E2E 增加匿名直取直传封面与发行包两条探测:默认 WARN,E2E_REQUIRE_PRIVATE_BUCKET=1 时按失败处理
- 里程碑第 7 条、pitfalls 与 decision-log 记录根因、修复与复验(严格模式 65 项 PASS,两处匿名直取都 403)
This commit is contained in:
kdletters
2026-09-28 19:20:21 +08:00
parent fb87e1d4ff
commit 25a992468d
8 changed files with 104 additions and 13 deletions
+30 -2
View File
@@ -39,6 +39,27 @@ function check(name, ok, detail = '') {
);
}
/**
* 探测对象是否被匿名直取。
*
* 这一条验的是「bucket / 对象 ACL」而不是接口行为:本地环境若还是公共读,默认只报 WARN,
* 设 E2E_REQUIRE_PRIVATE_BUCKET=1 时按失败处理,用于上线前的私有化复验。
*/
async function probeAnonymousObjectAccess(url, label) {
const response = await fetch(url);
if (response.status >= 400) {
check(`匿名直取${label}被拒绝`, true, `status=${response.status}`);
return;
}
if ((process.env.E2E_REQUIRE_PRIVATE_BUCKET ?? '').trim() === '1') {
check(`匿名直取${label}被拒绝`, false, `status=${response.status}`);
return;
}
console.log(
`WARN 匿名直取${label}返回 status=${response.status}:当前 bucket/对象 ACL 不是私有(可用 E2E_REQUIRE_PRIVATE_BUCKET=1 复验)。`,
);
}
async function api(path, options = {}) {
const { method = 'GET', token, body, headers = {}, binary } = options;
const finalHeaders = { ...ENVELOPE, ...headers };
@@ -592,6 +613,15 @@ async function main() {
Boolean(coverRead.data?.read?.signedUrl ?? coverRead.data?.signedUrl),
`status=${coverRead.status}`,
);
const signedCoverUrl =
coverRead.data?.read?.signedUrl ?? coverRead.data?.signedUrl;
if (signedCoverUrl) {
const coverHost = new URL(signedCoverUrl).host;
await probeAnonymousObjectAccess(
`https://${coverHost}/${cover.objectKey}`,
'直传上传的私有封面对象',
);
}
const shotRead = await api(
`/api/assets/read-url?objectKey=${encodeURIComponent(shot1.objectKey)}`,
);
@@ -1183,8 +1213,6 @@ async function main() {
const directObject = await fetch(
`https://${ossBucket}.${ossEndpoint}/${objectKey}`,
);
// 这一条验的是「环境里的 bucket/对象 ACL」,不是接口行为:本地 dev bucket 允许匿名读,
// 所以默认只报 WARN;上线前把 E2E_REQUIRE_PRIVATE_BUCKET=1 打开,让它在非私有环境里失败。
if (directObject.status >= 400) {
check(
'匿名直取私有 bucket 里的发行包对象被拒绝',