diff --git a/par-core/src/main/java/com/par/core/storage/QiniuStorageService.java b/par-core/src/main/java/com/par/core/storage/QiniuStorageService.java index 718937a..5b38e0c 100644 --- a/par-core/src/main/java/com/par/core/storage/QiniuStorageService.java +++ b/par-core/src/main/java/com/par/core/storage/QiniuStorageService.java @@ -87,19 +87,14 @@ public class QiniuStorageService implements StorageService { log.warn("Qiniu stat 失败 {}: {}", path, e.response != null ? e.response.error : e.getMessage()); } - // 直接 HTTP 拉取(公开桶),不用签名 - String rawUrl = "http://" + downloadDomain + "/" + path; + // 用 HTTPS 签名 URL 拉取 + String baseUrl = "https://" + downloadDomain + "/" + path; + String signedUrl = auth.privateDownloadUrl(baseUrl, 3600); try { - var req = HttpRequest.newBuilder().uri(URI.create(rawUrl)) + var req = HttpRequest.newBuilder().uri(URI.create(signedUrl)) .timeout(Duration.ofSeconds(10)).GET().build(); var resp = httpClient.send(req, HttpResponse.BodyHandlers.ofString()); if (resp.statusCode() == 200) return resp.body(); - // 公开桶失败,尝试签名URL - String signedUrl = auth.privateDownloadUrl(rawUrl, 3600); - req = HttpRequest.newBuilder().uri(URI.create(signedUrl)) - .timeout(Duration.ofSeconds(10)).GET().build(); - resp = httpClient.send(req, HttpResponse.BodyHandlers.ofString()); - if (resp.statusCode() == 200) return resp.body(); log.warn("Qiniu 下载失败 {}: HTTP {}", path, resp.statusCode()); } catch (Exception e) { log.warn("Qiniu 下载失败 {}: {}", path, e.getMessage());