【问题标题】:How to set header X-Content-Type-Options "nosniff" in Springboot application?如何在 Spring Boot 应用程序中设置标头 X-Content-Type-Options “nosniff”?
【发布时间】:2018-08-27 07:00:13
【问题描述】:

Anti-MIME-Sniffing 标头 X-Content-Type-Options 未设置为“nosniff”。

这允许旧版本的 Internet Explorer 和 Chrome 对响应正文执行 MIME 嗅探,从而可能导致响应正文被解释并显示为声明的内容类型以外的内容类型。当前(2014 年初)和旧版本的 Firefox 将使用声明的内容类型(如果设置了),而不是执行 MIME 嗅探。

【问题讨论】:

    标签: javascript java css jsp spring-boot


    【解决方案1】:
    1. 在您的构建中包含 spring 安全性 (build.gradle)

      编译组:'org.springframework.boot',名称:'spring-boot-starter-security',版本:'2.1.4.RELEASE'

    或 pom.xml。

    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-security</artifactId>
        <version>2.1.2.RELEASE</version>
    </dependency>
    

    参考:https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-security/2.1.2.RELEASE

    1. 在下面添加java代码。

      导入 org.springframework.security.config.annotation.web.builders.HttpSecurity;

      导入 org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;

      导入 org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

      @EnableWebSecurity
      public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
      
          @Override
          protected void configure(HttpSecurity http) throws Exception {
              http.csrf().disable();
      
          }
      }
      

    之前:

    Content-Type →application/json;charset=UTF-8
    Date →Wed, 15 May 2019 19:05:00 GMT
    X-Auth-Token →5178dc4e-eac5-40be-9ded-dcfa85c644b6
    X-B3-Spanid →3d9a5b2fd21b075c
    X-B3-Traceid →3d9a5b2fd21b075c
    X-Vcap-Request-Id →4988b251-c2c5-4c5f-558b-ed6bce724e1f
    Content-Length →992
    

    之后:

    X-B3-TraceId →51e54c950ae24fa1
    X-B3-SpanId →51e54c950ae24fa1
    X-Content-Type-Options →nosniff
    X-XSS-Protection →1; mode=block
    Cache-Control →no-cache, no-store, max-age=0, must-revalidate
    Pragma →no-cache
    Expires →0
    X-Frame-Options →DENY
    x-auth-token →92195048-341d-48a7-93a6-f6f0446f3f0c
    Content-Type →application/json;charset=UTF-8
    Transfer-Encoding →chunked
    Date →Fri, 17 May 2019 15:50:59 GMT
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2018-05-21
      • 1970-01-01
      • 1970-01-01
      • 2014-07-31
      • 2019-03-03
      • 2016-09-07
      • 1970-01-01
      • 2014-02-14
      相关资源
      最近更新 更多