Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

不建议使用顺序数字ID作为索引 #103

Closed
Lyt99 opened this issue Sep 8, 2020 · 4 comments · Fixed by #123
Closed

不建议使用顺序数字ID作为索引 #103

Lyt99 opened this issue Sep 8, 2020 · 4 comments · Fixed by #123
Labels
good first issue Good for newcomers
Projects

Comments

@Lyt99
Copy link

Lyt99 commented Sep 8, 2020

顺序数字ID(或者其它顺序ID)过于规律,导致很容易被遍历爬取内容
如果遇到公开的敏感信息(虽然正常来说不会存在),比如https://pasteme.cn/50000 可能会造成泄漏

建议使用乱序ID或者对纯数字进行混淆,不过后端开源的话也还是比较危险

@Lyt99
Copy link
Author

Lyt99 commented Sep 8, 2020

#95

@LucienShui LucienShui added the good first issue Good for newcomers label Sep 9, 2020
@chuanwise
Copy link

不使用顺序数字后,还可以增加一个 ip 多次访问不存在界面时认为其爬取内容而禁止其登陆网站若干小时的功能。

@LucienShui
Copy link
Owner

不使用顺序数字后,还可以增加一个 ip 多次访问不存在界面时认为其爬取内容而禁止其登陆网站若干小时的功能。

按照我的理解,不是所有人都有唯一的 IPv4 地址,所以我认为这样可能不行,容易误伤。

@LucienShui LucienShui added this to To do in 3.4.0 Jul 22, 2021
@LucienShui LucienShui linked a pull request Sep 20, 2021 that will close this issue
@LucienShui
Copy link
Owner

LucienShui commented Sep 20, 2021

#123 统一使用长度为 8 的随机字符串作为索引。

3.4.0 automation moved this from To do to Done Sep 20, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
good first issue Good for newcomers
Projects
3.4.0
Done
Development

Successfully merging a pull request may close this issue.

3 participants