ARTICLE DETAIL

建站实战干货

来自一线的建站与推广经验沉淀,每一条都经过真实交付验证。

transfer.sh 命令行文件分享服务器:从 curl 上传到自建部署的完整实战指南

2026/10/3 2:30:24 拓冰建站 浏览量
transfer.sh 命令行文件分享服务器:从 curl 上传到自建部署的完整实战指南 后端【免费下载链接】transfer.shEasy and fast file sharing from the command-line.项目地址https://gitcode.com/gh_mirrors/tr/transfer.sh点击查看免费下载本篇技术指南围绕 transfer.sh 项目展开这是一个用 Go 编写的、面向命令行的快速文件分享服务器代码同时包含了可直接运行的服务端实现让你既能使用公开实例完成上传即得链接的日常操作也能在几分钟内自建私有实例。读完本文你将掌握完整的 curl/wget 上传下载流程、Max-Downloads / Max-Days 等请求头控制、服务端 AES256 加密与删除令牌机制、S3 / Google Drive / Storj / 本地文件系统四种存储后端配置以及基于 Docker 与 Kubernetes 的部署方案。项目概览与定位transfer.sh 的核心目标只有一个从命令行用最简单的方式完成文件分享。它提供的是一个完整的 HTTP 服务端服务端接收PUT上传的任意文件返回一个带随机 token 的短链接任何人在有效期内通过该链接即可下载。当前代码库支持四种存储后端local本地文件系统s3Amazon S3 及兼容 S3 协议的对象存储gdriveGoogle DrivestorjStorj 去中心化存储网络。从 入口文件 可以看到程序主体通过cmd.New()创建命令行应用并执行所有能力都由 服务端核心 与 路由处理器 承载。安全提醒README 顶部明确标注了一个安全警告——IP 过滤器与 HTTP 认证存在通过未认证的X-Forwarded-For头伪造进行绕过的漏洞详见项目 issue #670。因此在公网部署时请务必结合防火墙、反向代理等外部手段加固不要仅依赖内置的 IP 白名单做访问控制。基础用法上传、下载、加密与删除上传文件最简单的方式是使用 curl 的--upload-file参数将本地文件直接推送到服务端$ curl -v --upload-file ./hello.txt https://transfer.sh/hello.txt服务端返回一串 URL包含随机 token 与文件名例如https://transfer.sh/1lDau/hello.txt。从源码看上传走的是 putHandler文件名会经过sanitize()清洗剥离控制字符、特殊 Unicode 分类并取path.Base随后生成一个随机 token长度由random-token-length决定见 token.go 中基于 crypto/rand 种子实现的字符集生成器文件本体与一个记录元数据的filename.metadata对象JSON 格式包含 ContentType、ContentLength、下载次数、MaxDownloads、MaxDate、DeletionToken 等字段一起写入存储后端。上传时加密客户端侧 GPG如果希望文件在传输前即已加密可先用 GPG 对称加密再上传$ gpg --armor --symmetric --output - /tmp/hello.txt | curl --upload-file - https://transfer.sh/test.txt下载并解密$ curl https://transfer.sh/1lDau/test.txt | gpg --decrypt --output /tmp/hello.txt上传文件到 VirusTotal 扫描在 URL 后追加/virustotal服务端会把文件提交给 VirusTotal 并返回分析结果的 permalink$ curl -X PUT --upload-file nhgbhhj https://transfer.sh/test.txt/virustotal该功能由 virustotal.go 中的virusTotalHandler实现需要配置virustotal-keyVirusTotal API key才能工作。删除文件每个文件在返回的响应头X-Url-Delete中带有唯一删除 URL用DELETE方法请求该 URL 即可删除$ curl -X DELETE X-Url-Delete Response Header URL删除的校验逻辑在 handlers.go 的 deleteHandler 与checkDeletionToken中请求路径中的deletionToken必须与上传时生成并写入 metadata 的DeletionToken完全一致否则返回 404。删除 token 是上传时由token(randomTokenLength) token(randomTokenLength)拼接生成的长度相当于两倍的上传路径 token这也是为什么 README 中random-token-length参数注明删除路径 token 是其两倍。请求头控制下载次数、存活天数与服务端加密这部分请求头是 transfer.sh 最具实用价值的能力全部通过 curl 的-H参数附加。Max-Downloads限制下载次数$ curl --upload-file ./hello.txt https://transfer.sh/hello.txt -H Max-Downloads: 1 # Limit the number of downloadsMax-Days设置自动过期天数$ curl --upload-file ./hello.txt https://transfer.sh/hello.txt -H Max-Days: 1 # Set the number of days before deletion从 metadataForRequest 的实现可以看到Max-Downloads被解析后写入 metadata 的MaxDownloads字段默认 -1 表示不限Max-Days被换算为time.Now().Add(time.Hour * 24 * v)存入MaxDate。每次下载时 checkMetadata 都会校验这两个条件——下载次数达到上限或过期都会返回错误且下载计数会在持有 per-file 锁lock(token, filename)基于sync.Map与sync.Mutex的前提下递增并回写 metadata。与之配套下载响应中还会返回X-Remaining-Downloads与X-Remaining-Days两个响应头方便脚本感知剩余额度。X-Encrypt-Password / X-Decrypt-Password服务端 AES256 加密$ curl --upload-file ./hello.txt https://your-transfersh-instance.tld/hello.txt -H X-Encrypt-Password: test # Encrypt the content server side with AES256 using test as password$ curl https://your-transfersh-instance.tld/BAYh0/hello.txt -H X-Decrypt-Password: test # Decrypt the content server side with AES256 using test as password重要警告README 原文强调请只在自建服务器上使用该功能——把文件交给第三方服务做服务端加密信任风险完全由你自己承担。实现上加密/解密通过 OpenPGP 对称加密完成attachEncryptionReader调用encrypt()见 handlers.go使用 AES256 密码套件packet.CipherAES256生成带 armor 包装的密文流解密时attachDecryptionReader先armor.Decode解包再以请求头携带的密码为 prompt 输入openpgp.ReadMessage密码错误会触发wrong password错误。上传时若带X-Encrypt-Passwordmetadata 会记录Encryptedtrue、原始 ContentType 存入DecryptedContentType、存储 ContentType 变为text/plain; charsetutf-8下载时只有同时带对X-Decrypt-Password才能还原出原始内容类型与长度见 getHandler。响应头X-Url-Delete 与删除链接每次上传成功后服务端通过X-Url-Delete响应头返回删除专用 URL。用-D -dump headers即可看到curl -sD - --upload-file ./hello.txt https://transfer.sh/hello.txt | grep -i -E transfer\.sh|x-url-delete x-url-delete: https://transfer.sh/hello.txt/BAYh0/hello.txt/PDw0NHPcqU https://transfer.sh/hello.txt/BAYh0/hello.txt第一行是X-Url-Delete响应头形如…/{token}/{filename}/{deletionToken}第二行是普通下载链接。脚本可以通过解析该响应头自动构造删除命令——这正是后文带删除链接的高级 Shell 函数的基础。链接别名强制下载与内联预览对于任意形如https://transfer.sh/{token}/{filename}的下载链接可以在 token 前插入动作前缀获得两种行为直接下载get 别名https://transfer.sh/1lDau/test.txt→https://transfer.sh/get/1lDau/test.txt内联预览inline 别名https://transfer.sh/1lDau/test.txt→https://transfer.sh/inline/1lDau/test.txt。路由层面由 server.go 的/{action:(?:download|get|inline)}/{token}/{filename}模式承载getHandler中根据action决定Content-Disposition是attachment还是inlineinline 模式下若无法判定内容类型会回退为text/plain; charsetutf-8以防 XSS并会对可嵌入 HTML 的内容类型如 html、xml、vtt、xsl 等见canContainsXSS做 bluemonday 的 UGC 策略净化。此外浏览器直接访问普通链接时previewHandler 会根据 Accept 头与 Referer 判断是否渲染预览页图片/视频/音频/文本/markdown 各有模板还附带二维码。自建部署参数表与两种 HTTPS 方案全部运行参数下表完整列出服务端支持的全部命令行参数、取值与对应环境变量环境变量与 flag 等价均可使用源码定义见 cmd/cmd.go| 参数 | 说明 | 默认值 | 环境变量 | |--- |---|---|--| | listener | http 监听地址如 127.0.0.1:8080 | 127.0.0.1:8080 | LISTENER | | profile-listener | profiler 监听地址默认 :6060 | | PROFILE_LISTENER | | force-https | 强制跳转 https | false | FORCE_HTTPS | | tls-listener | https 监听端口:443 | | TLS_LISTENER | | tls-listener-only | 仅启用 tls 监听 | | TLS_LISTENER_ONLY | | tls-cert-file | TLS 证书路径 | | TLS_CERT_FILE | | tls-private-key | TLS 私钥路径 | | TLS_PRIVATE_KEY | | http-auth-user | 上传的 basic http auth 用户名 | | HTTP_AUTH_USER | | http-auth-pass | 上传的 basic http auth 密码 | | HTTP_AUTH_PASS | | http-auth-htpasswd | basic http auth 的 htpasswd 文件路径 | | HTTP_AUTH_HTPASSWD | | http-auth-ip-whitelist | 免认证上传的 IP 白名单逗号分隔 | | HTTP_AUTH_IP_WHITELIST | | virustotal-key | VirusTotal API key | | VIRUSTOTAL_KEY | | ip-whitelist | 允许连接服务的 IP 列表逗号分隔 | | IP_WHITELIST | | ip-blacklist | 禁止连接服务的 IP 列表逗号分隔 | | IP_BLACKLIST | | temp-path | 临时目录 | 系统临时目录 | TEMP_PATH | | web-path | 静态前端文件路径开发或自定义前端 | | WEB_PATH | | proxy-path | 反向代理路径前缀开头的/会被修剪 | | PROXY_PATH | | proxy-port | 反向代理的端口 | | PROXY_PORT | | email-contact | 前端联系我们邮箱 | | EMAIL_CONTACT | | ga-key | 前端 Google Analytics key | | GA_KEY | | provider | 存储提供商 | | PROVIDER | | uservoice-key | 前端 UserVoice key | | USERVOICE_KEY | | aws-access-key | AWS access key | | AWS_ACCESS_KEY | | aws-secret-key | AWS secret key | | AWS_SECRET_KEY | | bucket | AWS bucket | | BUCKET | | s3-endpoint | 自定义 S3 endpoint | | S3_ENDPOINT | | s3-region | S3 bucket 区域 | eu-west-1 | S3_REGION | | s3-credentials-type | S3 凭证模式legacy或default-sdk-credential-chain | legacy | S3_CREDENTIALS_TYPE | | s3-no-multipart | 禁用 S3 分片上传 | false | S3_NO_MULTIPART | | s3-path-style | 强制 path-style URLMinio 必需 | false | S3_PATH_STYLE | | storj-access | Storj 项目的 Access Grant | | STORJ_ACCESS | | storj-bucket | Storj 项目中的 bucket | | STORJ_BUCKET | | basedir | local/gdrive 提供商的存储路径 | | BASEDIR | | gdrive-client-json-filepath | gdrive 的 OAuth client json 配置路径 | | GDRIVE_CLIENT_JSON_FILEPATH | | gdrive-local-config-path | gdrive 本地配置缓存目录 | | GDRIVE_LOCAL_CONFIG_PATH | | gdrive-chunk-size | gdrive 上传分片大小MB需低于可用内存默认 8 MB | 8 | GDRIVE_CHUNK_SIZE | | lets-encrypt-hosts | 使用 Lets Encrypt 的主机名逗号分隔 | | HOSTS | | log | 日志文件路径 | | LOG | | cors-domains | 允许 CORS 的域名列表逗号分隔设置即启用 CORS | | CORS_DOMAINS | | clamav-host | ClamAV 功能的主机 | | CLAMAV_HOST | | perform-clamav-prescan | 上传前用 ClamAV 预扫描clamav-host 必须是本地 clamd unix socket | | PERFORM_CLAMAV_PRESCAN | | rate-limit | 每分钟请求数 | | RATE_LIMIT | | max-upload-size | 最大上传大小KB | | MAX_UPLOAD_SIZE | | purge-days | 上传多少天后自动清理 | | PURGE_DAYS | | purge-interval | 自动清理运行间隔小时不适用于 S3 与 Storj | | PURGE_INTERVAL | | random-token-length | 上传路径随机 token 长度删除路径为其两倍 | 6源码默认 10 | RANDOM_TOKEN_LENGTH |注意README 参数表中listener默认标注为 :80、random-token-length默认标注为 6而当前仓库源码 cmd.go 中listener的默认值是127.0.0.1:8080、random-token-length默认值为 10以源码为准。使用 Lets Encrypt 自动证书若要用 Lets Encrypt 自动签发证书配置三个参数即可# 设置 lets-encrypt-hosts 为你的域名tls-listener 为 :443并启用 force-https transfer.sh --provider local --basedir /tmp/ --lets-encrypt-hosts example.com --tls-listener :443 --force-https实现上通过 UseLetsEncrypt 创建autocert.Manager证书缓存在./cache/目录HostPolicy校验请求主机必须是所配域名或其子域。使用自有证书# 设置 tls-listener 为 :443同时给出 force-https、tls-cert-file 与 tls-private-key transfer.sh --provider local --basedir /tmp/ --tls-listener :443 --force-https --tls-cert-file /path/cert.pem --tls-private-key /path/key.pem自有证书路径由 TLSConfig 通过tls.LoadX509KeyPair加载并作为GetCertificate回调使用。若只想用tls-listener-only则纯 TLS 监听、不启动 HTTP。本地开发与手动构建项目使用 Go ModulesGO111MODULE本地一条命令即可把服务跑起来local 提供商 8080 端口go run main.go --providerlocal --listener :8080 --temp-path/tmp/ --basedir/tmp/源码构建产物为transfersh可执行文件$ git clone gitgithub.com:dutchcoders/transfer.sh.git $ cd transfer.sh $ go build -o transfersh main.go如需查看版本信息transfer.sh version子命令会输出类似transfer.sh 0.0.0: Easy file sharing from the command line的内容版本号通过构建参数注入见 cmd.go。Docker 部署官方提供 Docker 镜像方便快速部署。镜像分两种变体区别仅在于以哪个用户运行进程。默认root 用户镜像docker run --publish 8080:8080 dutchcoders/transfer.sh:latest --provider local --basedir /tmp/[!WARNING] 官方不建议 WatchTower 之类的工具使用latest标签latest可能指向未发布的开发版、测试构建或旧版本补丁。请使用具体版本标签直到 transfer.sh 开始提供 major/minor 版本标签。最小权限镜像推荐以-noroot为后缀的镜像以最小权限运行UID/GID 均为 5000降低应用被攻破后的攻击面。官方 README 明确建议优先使用-norootdocker run --publish 8080:8080 dutchcoders/transfer.sh:latest-noroot --provider local --basedir /tmp/镜像标签| 标签 | 用途 | |--|--| | latest | 最新 CI 构建可能是 nightly、commit 或 tag 构建 | | latest-noroot | 同上但使用非 root 用户 | | nightly | 每天 UTC 午夜定时 CI 构建 | | nightly-noroot | 同上但使用非 root 用户 | | edge |main分支每次提交后的最新 CI 构建 | | edge-noroot | 同上但使用非 root 用户 | | vx.y.z| 打 tag 发布后的 CI 构建 | | vx.y.z-noroot | 同上但使用非 root 用户 |自定义构建容器自选 UID/GID如果使用 NFS 挂载等场景需要自定义 UID/GID可以自行构建# 构建参数 # * RUNAS: 为空则容器以 root 运行设置任意值则启用 UID/GID 选择。 # * PUID: 进程 UID需 RUNAS 非空默认 5000。 # * PGID: 进程 GID需 RUNAS 非空默认 5000。 docker build -t transfer.sh-noroot --build-arg RUNASdoesntmatter --build-arg PUID1337 --build-arg PGID1338 .从仓库 Dockerfile 可以看到镜像采用多阶段构建golang:alpine中编译CGO_ENABLED0静态链接、注入cmd.Version最终产物复制进scratch基础镜像RUNAS非空时会生成对应的/etc/passwd、/etc/shadow、/etc/group条目以实现非 root 运行。项目也提供了 Kubernetes 部署清单Helm chart 位于 k8s/transfer.sh包含 deployment、hpa、ingress、networkpolicy、pvc 等模板可作为生产环境编排参考。存储后端配置S3Amazon S3 与自定义兼容服务使用 AWS S3 bucket 只需指定以下选项均支持 flag 或环境变量二选一--provider s3--aws-access-key或环境变量AWS_ACCESS_KEY--aws-secret-key或环境变量AWS_SECRET_KEY--bucket或环境变量BUCKET--s3-region或环境变量S3_REGION凭证模式说明默认legacy模式要求同时提供静态的 access key 与 secret key显式设置--s3-credentials-type default-sdk-credential-chain或环境变量S3_CREDENTIALS_TYPEdefault-sdk-credential-chain则改用 AWS SDK 默认凭证链支持环境凭证、共享 AWS 配置文件、ECS 任务角色、EC2 实例配置文件以及 EKS IRSA 等来源。指定s3-region后无需再设置 endpointSDK 会自动选择正确 endpoint。自定义 S3 提供商使用非 AWS 的 S3 兼容存储如 MinIO时需要按云厂商文档指定s3-endpoint同时若服务要求 path-style URLMinIO 即如此需开启--s3-path-style。其余常用组合--s3-no-multipart可禁用 S3 分片上传。S3 存储实现见 s3.go其配套测试位于 s3_test.go。Storj 去中心化存储使用 Storj Network 作为存储后端需要指定--provider storj--storj-access或环境变量STORJ_ACCESS--storj-bucket或环境变量STORJ_BUCKET创建 Bucket 与 Access Grant 的准备工作登录 Storj 账户进入 Access Grant 菜单点击右上角 Wizard输入 access grant 名称点击Next按需做权限限制也可在 CLI 或浏览器中继续设置一个用作加密密钥的 Passphrase——务必妥善保存丢失后将永远无法解密你的文件复制生成的 access grant 即可启动 transfer.sh。出于安全考虑官方推荐将 access grant 与 bucket 名称都以环境变量方式提供export STORJ_BUCKETBUCKET NAME export STORJ_ACCESSACCESS GRANT transfer.sh --provider storjStorj 存储实现在 storj.go。Google Drive使用 Google Drive 需要指定--provider gdrive--gdrive-client-json-filepath--gdrive-local-config-path--basedir创建 Gdrive Client Json在 console.cloud.google.com 创建一个 OAuth Client ID下载 JSON 文件并放置到安全目录。启动示例go run main.go --provider gdrive --basedir /tmp/ --gdrive-client-json-filepath /[credential_dir] --gdrive-local-config-path [directory_to_save_config]gdrive-chunk-size控制上传分片大小MB默认取 Google API 默认分片大小换算值即 8 MB需低于可用内存。GDrive 存储实现在 gdrive.go。Shell 函数把文件分享变成一条命令简易版Bash / ash / zsh多文件打包为 zip将以下函数加入.bashrc、.zshrc或等价配置transfer() (if [ $# -eq 0 ]; then printf No arguments specified.\nUsage:\n transfer file|directory\n ... | transfer file_name\n2; return 1; fi; file_name$(basename $1); if [ -t 0 ]; then file$1; if [ ! -e $file ]; then echo $file: No such file or directory2; return 1; fi; if [ -d $file ]; then cd $file || return 1; file_name$file_name.zip; set -- zip -r -q - .; else set -- cat $file; fi; else set -- cat; fi; url$($ | curl --silent --show-error --progress-bar --upload-file - https://transfer.sh/$file_name); echo $url; )之后即可直接使用$ transfer hello.txt该函数会智能判断输入目录被自动zip -r打包后上传文件名追加.zip普通文件直接上传来自管道的 stdin 则以指定文件名上传。进阶版Bash / zsh输出删除命令、删除 token上传前二次确认展开查看完整函数transfer() { local file declare -a file_array file_array(${}) if [[ ${file_array[]} || ${1} --help || ${1} -h ]] then echo ${0} - Upload arbitrary files to \transfer.sh\. echo echo Usage: ${0} [options] [file]... echo echo OPTIONS: echo -h, --help echo show this message echo echo EXAMPLES: echo Upload a single file from the current working directory: echo ${0} \image.img\ echo echo Upload multiple files from the current working directory: echo ${0} \image.img\ \image2.img\ echo echo Upload a file from a different directory: echo ${0} \/tmp/some_file\ echo echo Upload all files from the current working directory. Be aware of the webservers rate limiting!: echo ${0} * echo echo Upload a single file from the current working directory and filter out the delete token and download link: echo ${0} \image.img\ | awk --field-separator\: \ /Delete token:/ { print \$2 } /Download link:/ { print \$2 } echo echo Show help text from \transfer.sh\: echo curl --request GET \https://transfer.sh\ return 0 else for file in ${file_array[]} do if [[ ! -f ${file} ]] then echo -e \e[01;31m${file} could not be found or is not a file.\e[0m 2 return 1 fi done unset file fi local upload_files local curl_output local awk_output du -c -k -L ${file_array[]} 2 # be compatible with bash if [[ ${ZSH_NAME} zsh ]] then read $upload_files?\e[01;31mDo you really want to upload the above files (${#file_array[]}$) to \transfer.sh\? (Y/n): \e[0m elif [[ ${BASH} *bash* ]] then read -p $\e[01;31mDo you really want to upload the above files (${#file_array[]}$) to \transfer.sh\? (Y/n): \e[0m upload_files fi case ${upload_files:-y} in y|Y) # for the sake of the progress bar, execute curl for each file. # the parameters --include and --form will suppress the progress bar. for file in ${file_array[]} do # show delete link and filter out the delete token from the response header after upload. # it is important to save curls stdout via a subshell to a variable or redirect it to another command, # which just redirects to stdout in order to have a sane output afterwards. # the progress bar is redirected to stderr and is only displayed, # if stdout is redirected to something; e.g. /dev/null, tee /dev/null or | some_command. # the response header is redirected to stdout, so redirecting stdout to /dev/null does not make any sense. # redirecting curls stderr to stdout (21) will suppress the progress bar. curl_output$(curl --request PUT --progress-bar --dump-header - --upload-file ${file} https://transfer.sh/) awk_output$(awk \ gsub(\r, , $0) tolower($1) ~ /x-url-delete/ \ { delete_link$2; print Delete command: curl --request DELETE \delete_link\; gsub(.*/, , delete_link); delete_tokendelete_link; print Delete token: delete_token; } END{ print Download link: $0; } ${curl_output}) # return the results via stdout, awk does not do this for some reason. echo -e ${awk_output}\n # avoid rate limiting as much as possible; nginx: too many requests. if (( ${#file_array[]} 4 )) then sleep 5 fi done ;; n|N) return 1 ;; *) echo -e \e[01;31mWrong input: ${upload_files}.\e[0m 2 return 1 esac }该函数逐文件用curl --request PUT --progress-bar --dump-header - --upload-file上传再用 awk 从响应头中提取x-url-delete同时打印出可直接复制的删除命令、删除 token 与下载链接超过 4 个文件时每次间隔 5 秒以规避nginx: too many requests限流。示例输出$ ls -lh total 20M -rw-r--r-- 1 some_username some_username 10M Apr 4 21:08 image.img -rw-r--r-- 1 some_username some_username 10M Apr 4 21:08 image2.img $ transfer image* 10240K image2.img 10240K image.img 20480K total Do you really want to upload the above files (2) to transfer.sh? (Y/n): ######################################################################################################################################################################################################################################## 100.0% Delete command: curl --request DELETE https://transfer.sh/wJw9pz/image2.img/mSctGx7pYCId Delete token: mSctGx7pYCId Download link: https://transfer.sh/wJw9pz/image2.img ######################################################################################################################################################################################################################################## 100.0% Delete command: curl --request DELETE https://transfer.sh/ljJc5I/image.img/nw7qaoiKUwCU Delete token: nw7qaoiKUwCU Download link: https://transfer.sh/ljJc5I/image.img $ transfer image.img | awk --field-separator: /Delete token:/ { print $2 } /Download link:/ { print $2 } 10240K image.img 10240K total Do you really want to upload the above files (1) to transfer.sh? (Y/n): ######################################################################################################################################################################################################################################## 100.0% tauN5dE3fWJe https://transfer.sh/MYkuqn/image.img更多实战组合备份、归档与自动化仓库 examples.md 提供了大量可直接套用的实战场景这里摘录几类最常用的备份 MySQL 并加密上传$ mysqldump --all-databases | gzip | gpg -ac -o- | curl -X PUT --upload-file - https://transfer.sh/test.txt归档目录并上传$ tar -czf - /var/log/journal | curl --upload-file - https://transfer.sh/journal.tar.gz一次上传多个文件multipart 表单$ curl -i -F filedata/tmp/hello.txt -F filedata/tmp/hello2.txt https://transfer.sh/一次性下载多个文件并打包为 zip / tar.gz逗号分隔多个{token}/{filename}$ curl https://transfer.sh/(15HKz/hello.txt,15HKz/hello.txt).tar.gz $ curl https://transfer.sh/(15HKz/hello.txt,15HKz/hello.txt).zip该能力由 server.go 的zipHandler/tarHandler/tarGzHandler实现见 handlers.go服务端流式打包zip 使用 Store 模式不压缩tar/tar.gz 则顺序写出。用 wget 上传$ wget --method PUT --body-file/tmp/file.tar https://transfer.sh/file.tar -O - -nv上传过滤后的文本$ grep pound /var/log/syslog | curl --upload-file - https://transfer.sh/pound.logClamAV 病毒扫描需配置clamav-host上传到/scan端点$ wget http://www.eicar.org/download/eicar.com $ curl -X PUT --upload-file ./eicar.com https://transfer.sh/eicar.com/scan加密 限制下载次数的传输函数transfer-encrypted -D 50 %file%默认限制 1 次下载$ curl -s https://transfer.sh/some/file | openssl aes-256-cbc -pbkdf2 -d output_filename此外 examples.md 还包含 fish-shell 的transfer函数、Windowstransfer.cmdPowerShell PUT 上传、以及上传后自动把 Linux/macOS/Windows 下载命令复制到剪贴板的transfer变体依赖 xclip/xsel 或 macOS 自带的 pbcopy/pbpaste可前往 examples.md 查阅完整代码。运维与安全要点综合上文源码证据自建实例时建议重点检查以下几点IP 过滤ip-whitelist/ip-blacklist支持单个 IPv4/IPv6 或 CIDR 网段如/24Allowed优先于Blocked但注意 README 顶部警告——X-Forwarded-For伪造可绕过因此生产环境应在反向代理层做真实 IP 校验HTTP 基础认证http-auth-user/http-auth-pass或http-auth-htpasswdhtpasswd 文件见 handlers.go 的 basicAuthHandler对上传类路由生效http-auth-ip-whitelist可让白名单 IP 免认证上传限流与大小限制rate-limit每分钟请求数基于 IP 的 token bucket 中间件见 server.go与max-upload-sizeKB超出返回 413可保护实例自动清理purge-dayspurge-interval小时启用后台定时清理purgeHandler不适用于 S3 与 Storj健康检查GET /health.html返回固定文本可用于负载均衡探活force-https开启时该路径不会被重定向。许可证与维护本项目代码与文档遵循 MIT 许可见 LICENSE版权归属 Remco Verhoef2011-2018与 Andrea Spacca2018-2020、Andrea Spacca 与 Stefan Benten2020 至今。当前维护者为 Andrea Spacca 与 Stefan Benten。官方立场明确如需长期使用请自行托管实例仓库不会为任何第三方公共实例做宣传。赞分享后端【免费下载链接】transfer.shEasy and fast file sharing from the command-line.项目地址https://gitcode.com/gh_mirrors/tr/transfer.sh点击查看免费下载相关推荐极速部署指南打造专属transfer.sh文件分享服务极速部署指南打造专属transfer.sh文件分享服务 transfer.sh是一款简单高效的命令行文件分享工具让你轻松实现文件的快速上传与分享。本指南将带后端transfer.sh 命令行文件分享实战指南上传下载、加密备份、病毒扫描与自动化脚本全解transfer.sh 命令行文件分享实战指南上传下载、加密备份、病毒扫描与自动化脚本全解 导读 本文以 transfer.sh 官方使用手册 example后端transfer.sh命令行下的简易快速文件共享指南transfer.sh命令行下的简易快速文件共享指南 项目介绍 transfer.sh 是一个开源项目由 DutchCoders 开发并维护它提供了一个简后端上一篇CANN ops-math 非连续 Tensor 完全指南基于 (shape, strides, offset) 的视图表示与内存寻址下一篇Security-101 第 1.3 课深度解读理解风险管理——从核心术语到风险评估的完整框架创作声明:本文部分内容由AI辅助生成(AIGC),仅供参考