【发布时间】:2019-10-11 09:23:16
【问题描述】:
在我的appsettings.json 中我添加了这行代码:
"Hsts": {
"HstsEnable": true
}
在launchSettings.json 我添加了https://localhost:5000:
"applicationUrl": "http://localhost:5001;https://localhost:5000"
然后,在Program.cs 我使用了这个网址:
return WebHost.CreateDefaultBuilder(args)
.UseKestrel(x => x.AddServerHeader = false)
.UseUrls("http://localhost:5001", "https://localhost:5000")
.UseStartup<Startup>()
在启动类中,在Configure 方法中,我从appSettings.json 获取Hsts 值:
if (Configuration.GetSection("Hsts").GetValue<bool>("HstsEnable"))
{
app.UseHsts();
}
app.UseHttpsRedirection();
在所有这些步骤之后,我无法获得Strict-Transport-Security。我从响应头中得到的只是:
cache-control: no-store,no-cache
content-type: application/json; charset=utf-8
pragma: no-cache
Hsts 从响应中删除了标题。如果没有所有这些代码行(在我的应用程序中设置hsts),我会得到这个响应头:
access-control-allow-credentials: true
access-control-allow-origin: *
access-control-expose-headers: Content-Disposition
cache-control: no-store,no-cache
content-type: application/json; charset=utf-8
date: Fri, 11 Oct 2019 09:21:30 GMT
pragma: no-cache
transfer-encoding: chunked
vary: Origin
x-frame-options: DENY
x-stackifyid: id
所以这个Hsts有问题。
如何在我上面提到的响应头中添加HSTS 头?我需要将标题硬编码到我的Configure 方法吗?
context.Response.Headers.Add("Strict-Transport-Security", "max-age=31536000");
【问题讨论】:
-
您提出的测试请求所使用的 URL 是什么?
-
@KirkLarkin
http://localhost:5001/ -
HSTS 中间件不会为环回地址上的请求添加 HSTS 标头。请参阅docs(该部分的末尾)。
标签: c# asp.net-core asp.net-web-api asp.net-core-2.2