CSP 内容安全策略,主要可用于防范XSS注入
具体相关文档参考:
https://developer.mozilla.org/zh-CN/docs/Web/HTTP/Headers/Content-Security-Policy
https://cloud.tencent.com/developer/section/1189862
项目中 nginx 配置,需要配置在server下:
###frame 同源策略
add_header X-Frame-Options SAMEORIGIN;
###CSP防护
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline';font-src 'self' data:; img-src 'self' data: 'unsafe-inline' https:; style-src 'self' 'unsafe-inline';frame-ancestors 'self'; frame-src 'self';connect-src https:";
###开启XSS防护
add_header X-Xss-Protection "1";
###资源解析
add_header X-Content-Type-Options nosniff;
###HSTS防护
add_header Strict-Transport-Security "max-age=172800; includeSubDomains";

2525

被折叠的 条评论
为什么被折叠?



