【问题标题】:ASP .NET Core no HSTS header in response headersASP .NET Core 响应标头中没有 HSTS 标头
【发布时间】:2019-10-11 09:23:16
【问题描述】:

在我的appsettings.json 中我添加了这行代码:

"Hsts": {
    "HstsEnable": true
 }

在launchSettings.json 我添加了https://localhost:5000:

"applicationUrl": "http://localhost:5001;https://localhost:5000"

然后,在Program.cs 我使用了这个网址:

 return WebHost.CreateDefaultBuilder(args)
            .UseKestrel(x => x.AddServerHeader = false)
            .UseUrls("http://localhost:5001", "https://localhost:5000")
            .UseStartup<Startup>()

在启动类中,在Configure 方法中,我从appSettings.json 获取Hsts 值:

if (Configuration.GetSection("Hsts").GetValue<bool>("HstsEnable"))
{
    app.UseHsts();
}

app.UseHttpsRedirection();

在所有这些步骤之后,我无法获得Strict-Transport-Security。我从响应头中得到的只是:

 cache-control: no-store,no-cache 
 content-type: application/json; charset=utf-8 
 pragma: no-cache 

Hsts 从响应中删除了标题。如果没有所有这些代码行(在我的应用程序中设置hsts),我会得到这个响应头:

access-control-allow-credentials: true 
access-control-allow-origin: * 
access-control-expose-headers: Content-Disposition 
cache-control: no-store,no-cache 
content-type: application/json; charset=utf-8 
date: Fri, 11 Oct 2019 09:21:30 GMT 
pragma: no-cache 
transfer-encoding: chunked 
vary: Origin 
x-frame-options: DENY 
x-stackifyid: id

所以这个Hsts有问题。

如何在我上面提到的响应头中添加HSTS 头?我需要将标题硬编码到我的Configure 方法吗?

context.Response.Headers.Add("Strict-Transport-Security", "max-age=31536000");

【问题讨论】:

  • 您提出的测试请求所使用的 URL 是什么?
  • @KirkLarkin http://localhost:5001/
  • HSTS 中间件不会为环回地址上的请求添加 HSTS 标头。请参阅docs(该部分的末尾)。

标签: c# asp.net-core asp.net-web-api asp.net-core-2.2


【解决方案1】:

来自HTTP Strict Transport Security Protocol (HSTS)的官方文档

UseHsts 不包括以下环回主机:

  • localhost : IPv4 环回地址。

  • 127.0.0.1 : IPv4 环回地址。

  • [::1] : IPv6 环回地址。

您可以尝试发布网络应用并检查标题 Strict-Transport-Security。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2020-03-12
    • 2023-04-10
    • 1970-01-01
    • 2018-06-20
    • 1970-01-01
    • 2018-02-25
    • 1970-01-01
    • 2020-04-21
    相关资源
    最近更新 更多