Ir al contenido

Secure

El middleware Secure proporciona protección contra cross-site scripting (XSS), content type sniffing, clickjacking, conexiones inseguras y otros ataques de inyección de código.

Todo el middleware principal reside en el paquete middleware:

import "github.com/labstack/echo/v5/middleware"
e.Use(middleware.Secure())
e := echo.New()
e.Use(middleware.SecureWithConfig(middleware.SecureConfig{
XSSProtection: "",
ContentTypeNosniff: "",
XFrameOptions: "",
HSTSMaxAge: 3600,
ContentSecurityPolicy: "default-src 'self'",
}))

SecureConfig · github.com/labstack/echo/v5@5196b9b

Las descripciones de los campos se generan a partir de comentarios del código fuente en inglés.

Campos del código fuente
CampoTipoDescripciónFuente
Skipper Skipper Skipper defines a function to skip middleware. L15
XSSProtection string XSSProtection provides protection against cross-site scripting attack (XSS) by setting the `X-XSS-Protection` header. Optional. Default value "1; mode=block". L20
ContentTypeNosniff string ContentTypeNosniff provides protection against overriding Content-Type header by setting the `X-Content-Type-Options` header. Optional. Default value "nosniff". L25
XFrameOptions string XFrameOptions can be used to indicate whether or not a browser should be allowed to render a page in a <frame>, <iframe> or <object> . Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.provides protection against clickjacking. Optional. Default value "SAMEORIGIN". Possible values: - "SAMEORIGIN" - The page can only be displayed in a frame on the same origin as the page itself. - "DENY" - The page cannot be displayed in a frame, regardless of the site attempting to do so. - "ALLOW-FROM uri" - The page can only be displayed in a frame on the specified origin. L37
HSTSMaxAge int HSTSMaxAge sets the `Strict-Transport-Security` header to indicate how long (in seconds) browsers should remember that this site is only to be accessed using HTTPS. This reduces your exposure to some SSL-stripping man-in-the-middle (MITM) attacks. Optional. Default value 0. L44
HSTSExcludeSubdomains bool HSTSExcludeSubdomains won't include subdomains tag in the `Strict Transport Security` header, excluding all subdomains from security policy. It has no effect unless HSTSMaxAge is set to a non-zero value. Optional. Default value false. L50
ContentSecurityPolicy string ContentSecurityPolicy sets the `Content-Security-Policy` header providing security against cross-site scripting (XSS), clickjacking and other code injection attacks resulting from execution of malicious content in the trusted web page context. Optional. Default value "". L57
CSPReportOnly bool CSPReportOnly would use the `Content-Security-Policy-Report-Only` header instead of the `Content-Security-Policy` header. This allows iterative updates of the content security policy by only reporting the violations that would have occurred instead of blocking the resource. Optional. Default value false. L64
HSTSPreloadEnabled bool HSTSPreloadEnabled will add the preload tag in the `Strict Transport Security` header, which enables the domain to be included in the HSTS preload list maintained by Chrome (and used by Firefox and Safari): https://hstspreload.org/ Optional. Default value false. L70
ReferrerPolicy string ReferrerPolicy sets the `Referrer-Policy` header providing security against leaking potentially sensitive request paths to third parties. Optional. Default value "". L75
Funciones del código fuente
TipoFuente
func Secure() echo.MiddlewareFunc L91
func SecureWithConfig(config SecureConfig) echo.MiddlewareFunc L96
var DefaultSecureConfig = SecureConfig{
Skipper: DefaultSkipper,
XSSProtection: "1; mode=block",
ContentTypeNosniff: "nosniff",
XFrameOptions: "SAMEORIGIN",
HSTSPreloadEnabled: false,
}

Actualización de seguridad de Echo (v5.4.0 / v4.16.0)

Sección titulada «Actualización de seguridad de Echo (v5.4.0 / v4.16.0)»

HSTS se envía cuando Context#Scheme() es https, no por una cabecera X-Forwarded-Proto: https sin verificar. Si un proxy público termina TLS, confía en su rango y haz que sobrescriba esa cabecera; de lo contrario puede faltar HSTS.