写入对象存储时下发对象级 ACL,修掉发行包可匿名直取
Project CI / AI game creator shell Rust crates (push) Successful in 1m30s
Project CI / AI game creator shell Rust smoke (push) Successful in 1m52s
Project CI / Backend tests (push) Successful in 4m55s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 8m4s
Project CI / Native shell tests (push) Successful in 6m20s
Project CI / Frontend tests (push) Successful in 2m11s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 9m6s
Project CI / AI game creator shell web tests (push) Successful in 1m40s
Project CI / Repository checks (push) Successful in 2m12s
Project CI / AI game creator shell Rust crates (push) Successful in 1m30s
Project CI / AI game creator shell Rust smoke (push) Successful in 1m52s
Project CI / Backend tests (push) Successful in 4m55s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 8m4s
Project CI / Native shell tests (push) Successful in 6m20s
Project CI / Frontend tests (push) Successful in 2m11s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 9m6s
Project CI / AI game creator shell web tests (push) Successful in 1m40s
Project CI / Repository checks (push) Successful in 2m12s
- platform-oss 的内部 PUT 与分片追加显式下发 x-oss-object-acl(Private 为 private、Public 为 public-read),OssAppendInternalObjectRequest 增加 access 字段 - 直传 policy 增加 x-oss-object-acl 条件,表单字段与 shared-contracts 的 DirectUploadTicketFormFields 同步新增并透传到 ticket 响应 - 媒体链路 E2E 增加匿名直取直传封面与发行包两条探测:默认 WARN,E2E_REQUIRE_PRIVATE_BUCKET=1 时按失败处理 - 里程碑第 7 条、pitfalls 与 decision-log 记录根因、修复与复验(严格模式 65 项 PASS,两处匿名直取都 403)
This commit is contained in:
@@ -39,6 +39,27 @@ function check(name, ok, detail = '') {
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* 探测对象是否被匿名直取。
|
||||
*
|
||||
* 这一条验的是「bucket / 对象 ACL」而不是接口行为:本地环境若还是公共读,默认只报 WARN,
|
||||
* 设 E2E_REQUIRE_PRIVATE_BUCKET=1 时按失败处理,用于上线前的私有化复验。
|
||||
*/
|
||||
async function probeAnonymousObjectAccess(url, label) {
|
||||
const response = await fetch(url);
|
||||
if (response.status >= 400) {
|
||||
check(`匿名直取${label}被拒绝`, true, `status=${response.status}`);
|
||||
return;
|
||||
}
|
||||
if ((process.env.E2E_REQUIRE_PRIVATE_BUCKET ?? '').trim() === '1') {
|
||||
check(`匿名直取${label}被拒绝`, false, `status=${response.status}`);
|
||||
return;
|
||||
}
|
||||
console.log(
|
||||
`WARN 匿名直取${label}返回 status=${response.status}:当前 bucket/对象 ACL 不是私有(可用 E2E_REQUIRE_PRIVATE_BUCKET=1 复验)。`,
|
||||
);
|
||||
}
|
||||
|
||||
async function api(path, options = {}) {
|
||||
const { method = 'GET', token, body, headers = {}, binary } = options;
|
||||
const finalHeaders = { ...ENVELOPE, ...headers };
|
||||
@@ -592,6 +613,15 @@ async function main() {
|
||||
Boolean(coverRead.data?.read?.signedUrl ?? coverRead.data?.signedUrl),
|
||||
`status=${coverRead.status}`,
|
||||
);
|
||||
const signedCoverUrl =
|
||||
coverRead.data?.read?.signedUrl ?? coverRead.data?.signedUrl;
|
||||
if (signedCoverUrl) {
|
||||
const coverHost = new URL(signedCoverUrl).host;
|
||||
await probeAnonymousObjectAccess(
|
||||
`https://${coverHost}/${cover.objectKey}`,
|
||||
'直传上传的私有封面对象',
|
||||
);
|
||||
}
|
||||
const shotRead = await api(
|
||||
`/api/assets/read-url?objectKey=${encodeURIComponent(shot1.objectKey)}`,
|
||||
);
|
||||
@@ -1183,8 +1213,6 @@ async function main() {
|
||||
const directObject = await fetch(
|
||||
`https://${ossBucket}.${ossEndpoint}/${objectKey}`,
|
||||
);
|
||||
// 这一条验的是「环境里的 bucket/对象 ACL」,不是接口行为:本地 dev bucket 允许匿名读,
|
||||
// 所以默认只报 WARN;上线前把 E2E_REQUIRE_PRIVATE_BUCKET=1 打开,让它在非私有环境里失败。
|
||||
if (directObject.status >= 400) {
|
||||
check(
|
||||
'匿名直取私有 bucket 里的发行包对象被拒绝',
|
||||
|
||||
Reference in New Issue
Block a user