diff --git a/handlers/http_handler.py b/handlers/http_handler.py index 798aa17..e185625 100644 --- a/handlers/http_handler.py +++ b/handlers/http_handler.py @@ -343,17 +343,20 @@ class MirrorServerHandler(BaseHTTPRequestHandler): # 任何方法都公开 for endpoint in public_any: - if check_path == endpoint or check_path.startswith(endpoint + '/'): + ep = endpoint.rstrip('/') + if check_path == ep or check_path.startswith(ep + '/'): return True if method in ('GET', 'HEAD'): - # 只读公开端点放行 + # 只读公开端点放行(去尾斜杠后按前缀匹配,避免双斜杠不命中) for endpoint in public_get: - if check_path == endpoint or check_path.startswith(endpoint + '/'): + ep = endpoint.rstrip('/') + if check_path == ep or check_path.startswith(ep + '/'): return True # 其余 GET: 命中受保护前缀才需要认证 for endpoint in protected_endpoints: - if check_path.startswith(endpoint): + ep = endpoint.rstrip('/') + if check_path == ep or check_path.startswith(ep + '/'): return self._do_auth(auth_type) return True