如何在生产日志文件中禁用Rails RoutingError堆栈跟踪打印输出?

16
在我的生产环境Rails应用程序中,我收到了各种随机攻击的请求,这些攻击请求asp、zip和rar文件。Rails按预期呈现404页面,但我的生产日志文件中充满了类似以下内容的RoutingError堆栈跟踪转储。
我的问题是:我是否可以在Apache/Passenger中阻止具有某些模式的URL?或者至少,我是否可以配置Rails仅记录错误本身,而不打印整个堆栈跟踪?谢谢!
Processing ApplicationController#index (for 100.222.237.7 at 2011-03-22 10:59:54) [GET]

ActionController::RoutingError (No route matches "/include/upfile_flash.asp" with {:host=>"www.myhost.com", :method=>:get, :domain=>"myhost.com", :subdomain=>"www"}):
  passenger (2.2.15) lib/phusion_passenger/rack/request_handler.rb:92:in `process_request'
  passenger (2.2.15) lib/phusion_passenger/abstract_request_handler.rb:207:in `main_loop'
  passenger (2.2.15) lib/phusion_passenger/railz/application_spawner.rb:441:in `start_request_handler'
  passenger (2.2.15) lib/phusion_passenger/railz/application_spawner.rb:381:in `handle_spawn_application'
  passenger (2.2.15) lib/phusion_passenger/utils.rb:252:in `safe_fork'
  passenger (2.2.15) lib/phusion_passenger/railz/application_spawner.rb:377:in `handle_spawn_application'
  passenger (2.2.15) lib/phusion_passenger/abstract_server.rb:352:in `__send__'
  passenger (2.2.15) lib/phusion_passenger/abstract_server.rb:352:in `main_loop'
  passenger (2.2.15) lib/phusion_passenger/abstract_server.rb:196:in `start_synchronously'
  passenger (2.2.15) lib/phusion_passenger/abstract_server.rb:163:in `start'
  passenger (2.2.15) lib/phusion_passenger/railz/application_spawner.rb:222:in `start'
  passenger (2.2.15) lib/phusion_passenger/spawn_manager.rb:253:in `spawn_rails_application'
  passenger (2.2.15) lib/phusion_passenger/abstract_server_collection.rb:126:in `lookup_or_add'
  passenger (2.2.15) lib/phusion_passenger/spawn_manager.rb:247:in `spawn_rails_application'
  passenger (2.2.15) lib/phusion_passenger/abstract_server_collection.rb:80:in `synchronize'
  passenger (2.2.15) lib/phusion_passenger/abstract_server_collection.rb:79:in `synchronize'
  passenger (2.2.15) lib/phusion_passenger/spawn_manager.rb:246:in `spawn_rails_application'
  passenger (2.2.15) lib/phusion_passenger/spawn_manager.rb:145:in `spawn_application'
  passenger (2.2.15) lib/phusion_passenger/spawn_manager.rb:278:in `handle_spawn_application'
  passenger (2.2.15) lib/phusion_passenger/abstract_server.rb:352:in `__send__'
  passenger (2.2.15) lib/phusion_passenger/abstract_server.rb:352:in `main_loop'
  passenger (2.2.15) lib/phusion_passenger/abstract_server.rb:196:in `start_synchronously'

Rendering /myapp/public/404.html (404 Not Found)
2个回答

10

Rails 4和5的答案:

match '*any', to: 'not_found#anything', via: [:get, :post]
为了匹配通配符参数,它必须被分配一个名称 - 在这种情况下为any

为了匹配通配符参数,它必须被分配一个名称 - 在这种情况下为any

class NotFoundController < ApplicationController
  def anything
    Logger.new('log/not_found.log').info(request.fullpath)
    # To render nothing:
    # head :not_found #Rails 5
    # render nothing: true, status: :not_found # for Rails 4

    #To render 404 page
    render file: 'public/404.html', status: :not_found, layout: false
  end
end

如果您正在使用ActiveStorage,则需要添加一个限制条件,请参见https://dev59.com/JrXna4cB1Zd3GeqPK3Pi - Alon Burg

9
您可以在所有其他路由之后添加一个捕获所有路由,以捕获此内容并呈现您选择的控制器/操作:
match '*' => 'errors#not_found'

你甚至可以选择只匹配 .asp 或其他文件扩展名(如果你想的话):
match '*.:format' => 'errors#not_found', :constraints => {:format => /(asp|zip|rar)/i}

网页内容由stack overflow 提供, 点击上面的
可以查看英文原文,
原文链接