All Products
Search
Document Center

Cloud Config:Enable hotlink protection for an OSS bucket

Last Updated:Jun 16, 2026

Checks whether hotlink protection is enabled for an OSS bucket.

Scenarios

Hotlink protection allows you to configure a referer whitelist for an OSS bucket to prevent unauthorized access to your data and resources.

Threat level

Default threat level: Low.

You can change the threat level based on your business requirements.

Detection logic

  • An OSS bucket is considered compliant if hotlink protection is enabled.

  • An OSS bucket is considered non-compliant if hotlink protection is not enabled. To fix this issue, see Remediation.

Rule details

Parameter

Description

Rule name

Enable hotlink protection for an OSS bucket

Rule identifier

oss-bucket-referer-enabled

Tags

OSS, Bucket

Auto-correction

Not supported

Rule trigger mechanism

Configuration change

Supported resource types

OSS bucket

Rule input parameters

allowEmptyReferer (Default value: true)

Remediation

Enable hotlink protection for the OSS bucket. For more information, see Configure hotlink protection.