nginx CSP 防护

CSP 内容安全策略,主要可用于防范XSS注入

具体相关文档参考:
https://developer.mozilla.org/zh-CN/docs/Web/HTTP/Headers/Content-Security-Policy

https://cloud.tencent.com/developer/section/1189862

项目中 nginx 配置,需要配置在server下:

###frame 同源策略
add_header X-Frame-Options SAMEORIGIN;
###CSP防护
add_header  Content-Security-Policy  "default-src 'self'; script-src 'self' 'unsafe-inline';font-src 'self' data:; img-src 'self'  data: 'unsafe-inline' https:; style-src 'self' 'unsafe-inline';frame-ancestors 'self'; frame-src 'self';connect-src https:";
###开启XSS防护
add_header X-Xss-Protection "1";
###资源解析
add_header X-Content-Type-Options nosniff;
###HSTS防护
add_header Strict-Transport-Security "max-age=172800; includeSubDomains";

你可能感兴趣的:(基础知识)