Home Backend Development Golang golang static service hidden

golang static service hidden

May 10, 2023 pm 03:41 PM

When using Go language to develop projects or services, we sometimes need to provide static files or resources in the project, such as style sheets, pictures, HTML files, etc. However, while providing these resources, we do not want to expose these files to the public network as this may cause some security issues. So, in this article, we will explore how to use Go language to serve static files or resources and hide them.

Traditional method

In the traditional method, we can serve static files or resources by reading the paths of static files or resources in the program and sending these paths to the browser. resource. This process often includes the following steps:

  1. Create a route processor.
  2. Parse the request path and map it to a local file path.
  3. If the file exists, open it and send it to the browser.
  4. If the file does not exist, return 404 error code.

The disadvantage of this method is that when the file is accessed, the full file path will be exposed in the browser's address bar. This security flaw may lead to vulnerabilities because attackers can obtain path information from the browser to launch attacks.

Hide files

In order to hide the file directory, we can use the FileServer function in the built-in net/http package of Go language. The FileServer function can access the local file system directory and return the file content, and also automatically handles HTTP requests and so on. To use the FileServer function, we first need to create a new route processor and map it to our file server:

func main() {
    http.Handle("/static/", http.StripPrefix("/static/", http.FileServer(http.Dir("static"))))
    http.ListenAndServe(":8080", nil)
}
Copy after login

where /static/ is the virtual directory we want to use, and static is the local file The actual directory in the system. Using the http.StripPrefix() function can help us remove the path prefix of static files. The http.FileServer() function creates a new file server instance.

File path

When using this method, the path displayed on the browser will only show the virtual directory we set. In this way, our file directory can be hidden. For example, for a file called test.html, if we place it in the /static directory of the local file system, then it will be accessible through http://localhost:8080/static/test.html.

Use gzip compression

In addition to hiding file paths, we can also use gzip compression technology to further improve performance. By using gzip compression, we can reduce the file size sent to the client, thus improving loading speed and client response time. To use gzip compression, we need to add some code to the route processor:

func main() {
    staticHandler := http.StripPrefix("/static/", http.FileServer(http.Dir("static")))
    http.Handle("/static/", gzipFileServer(staticHandler))
    http.ListenAndServe(":8080", nil)
}

func gzipFileServer(handler http.Handler) http.HandlerFunc {
    return func(w http.ResponseWriter, r *http.Request) {
        if strings.Contains(r.Header.Get("Accept-Encoding"), "gzip") {
            w.Header().Set("Content-Encoding", "gzip")
            gz := gzip.NewWriter(w)
            defer gz.Close()
            gzr := gzipResponseWriter{Writer: gz, ResponseWriter: w}
            handler.ServeHTTP(gzr, r)
            return
        }
        handler.ServeHTTP(w, r)
    }
}

type gzipResponseWriter struct {
    io.Writer
    http.ResponseWriter
}

func (w gzipResponseWriter) Write(b []byte) (int, error) {
    return w.Writer.Write(b)
}
Copy after login

This route processor is still similar to the previous one, except that we use a new gzipFileServer function to handle the request. In it, we parse the Accept-Encoding field in the request header and, if it contains gzip, process the file using gzip compression. Otherwise, we will use the original file for processing.

When the compression is completed, we need to set the Content-Encoding in the response header to gzip to ensure that the client can correctly decompress the response.

In fact, this is just a simple example. In practice, we need to integrate the above code into our own service and conduct more testing and optimization.

Summary

By using the FileServer function provided by the Go language, we can hide static files or resources to protect their security. In addition, we can also use gzip compression technology to improve performance. These technologies can help us build more secure and efficient static files or resource services, and they are all very practical skills when developing using the Go language.

The above is the detailed content of golang static service hidden. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

What are the vulnerabilities of Debian OpenSSL What are the vulnerabilities of Debian OpenSSL Apr 02, 2025 am 07:30 AM

OpenSSL, as an open source library widely used in secure communications, provides encryption algorithms, keys and certificate management functions. However, there are some known security vulnerabilities in its historical version, some of which are extremely harmful. This article will focus on common vulnerabilities and response measures for OpenSSL in Debian systems. DebianOpenSSL known vulnerabilities: OpenSSL has experienced several serious vulnerabilities, such as: Heart Bleeding Vulnerability (CVE-2014-0160): This vulnerability affects OpenSSL 1.0.1 to 1.0.1f and 1.0.2 to 1.0.2 beta versions. An attacker can use this vulnerability to unauthorized read sensitive information on the server, including encryption keys, etc.

How do you write unit tests in Go? How do you write unit tests in Go? Mar 21, 2025 pm 06:34 PM

The article discusses writing unit tests in Go, covering best practices, mocking techniques, and tools for efficient test management.

How do you use the pprof tool to analyze Go performance? How do you use the pprof tool to analyze Go performance? Mar 21, 2025 pm 06:37 PM

The article explains how to use the pprof tool for analyzing Go performance, including enabling profiling, collecting data, and identifying common bottlenecks like CPU and memory issues.Character count: 159

What libraries are used for floating point number operations in Go? What libraries are used for floating point number operations in Go? Apr 02, 2025 pm 02:06 PM

The library used for floating-point number operation in Go language introduces how to ensure the accuracy is...

What is the problem with Queue thread in Go's crawler Colly? What is the problem with Queue thread in Go's crawler Colly? Apr 02, 2025 pm 02:09 PM

Queue threading problem in Go crawler Colly explores the problem of using the Colly crawler library in Go language, developers often encounter problems with threads and request queues. �...

PostgreSQL monitoring method under Debian PostgreSQL monitoring method under Debian Apr 02, 2025 am 07:27 AM

This article introduces a variety of methods and tools to monitor PostgreSQL databases under the Debian system, helping you to fully grasp database performance monitoring. 1. Use PostgreSQL to build-in monitoring view PostgreSQL itself provides multiple views for monitoring database activities: pg_stat_activity: displays database activities in real time, including connections, queries, transactions and other information. pg_stat_replication: Monitors replication status, especially suitable for stream replication clusters. pg_stat_database: Provides database statistics, such as database size, transaction commit/rollback times and other key indicators. 2. Use log analysis tool pgBadg

Transforming from front-end to back-end development, is it more promising to learn Java or Golang? Transforming from front-end to back-end development, is it more promising to learn Java or Golang? Apr 02, 2025 am 09:12 AM

Backend learning path: The exploration journey from front-end to back-end As a back-end beginner who transforms from front-end development, you already have the foundation of nodejs,...

How to solve the user_id type conversion problem when using Redis Stream to implement message queues in Go language? How to solve the user_id type conversion problem when using Redis Stream to implement message queues in Go language? Apr 02, 2025 pm 04:54 PM

The problem of using RedisStream to implement message queues in Go language is using Go language and Redis...

See all articles