セキュア
Secure ミドルウェアは、クロスサイトスクリプティング(XSS)、コンテンツタイプスニッフィング、 クリックジャッキング、安全でない接続、その他のコードインジェクション攻撃への防御を提供します。
すべてのコアミドルウェアは middleware パッケージに含まれています:
import "github.com/labstack/echo/v5/middleware"e.Use(middleware.Secure())カスタム設定
Section titled “カスタム設定”e := echo.New()e.Use(middleware.SecureWithConfig(middleware.SecureConfig{ XSSProtection: "", ContentTypeNosniff: "", XFrameOptions: "", HSTSMaxAge: 3600, ContentSecurityPolicy: "default-src 'self'",}))SecureConfig · github.com/labstack/echo/v5@5196b9b
フィールドの説明は英語のソースコードのコメントから生成されています。
| フィールド | 型 | 説明 | ソース |
|---|---|---|---|
Skipper | Skipper | Skipper defines a function to skip middleware. | L15 |
XSSProtection | string | XSSProtection provides protection against cross-site scripting attack (XSS) by setting the `X-XSS-Protection` header. Optional. Default value "1; mode=block". | L20 |
ContentTypeNosniff | string | ContentTypeNosniff provides protection against overriding Content-Type header by setting the `X-Content-Type-Options` header. Optional. Default value "nosniff". | L25 |
XFrameOptions | string | XFrameOptions can be used to indicate whether or not a browser should be allowed to render a page in a <frame>, <iframe> or <object> . Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.provides protection against clickjacking. Optional. Default value "SAMEORIGIN". Possible values: - "SAMEORIGIN" - The page can only be displayed in a frame on the same origin as the page itself. - "DENY" - The page cannot be displayed in a frame, regardless of the site attempting to do so. - "ALLOW-FROM uri" - The page can only be displayed in a frame on the specified origin. | L37 |
HSTSMaxAge | int | HSTSMaxAge sets the `Strict-Transport-Security` header to indicate how long (in seconds) browsers should remember that this site is only to be accessed using HTTPS. This reduces your exposure to some SSL-stripping man-in-the-middle (MITM) attacks. Optional. Default value 0. | L44 |
HSTSExcludeSubdomains | bool | HSTSExcludeSubdomains won't include subdomains tag in the `Strict Transport Security` header, excluding all subdomains from security policy. It has no effect unless HSTSMaxAge is set to a non-zero value. Optional. Default value false. | L50 |
ContentSecurityPolicy | string | ContentSecurityPolicy sets the `Content-Security-Policy` header providing security against cross-site scripting (XSS), clickjacking and other code injection attacks resulting from execution of malicious content in the trusted web page context. Optional. Default value "". | L57 |
CSPReportOnly | bool | CSPReportOnly would use the `Content-Security-Policy-Report-Only` header instead of the `Content-Security-Policy` header. This allows iterative updates of the content security policy by only reporting the violations that would have occurred instead of blocking the resource. Optional. Default value false. | L64 |
HSTSPreloadEnabled | bool | HSTSPreloadEnabled will add the preload tag in the `Strict Transport Security` header, which enables the domain to be included in the HSTS preload list maintained by Chrome (and used by Firefox and Safari): https://hstspreload.org/ Optional. Default value false. | L70 |
ReferrerPolicy | string | ReferrerPolicy sets the `Referrer-Policy` header providing security against leaking potentially sensitive request paths to third parties. Optional. Default value "". | L75 |
デフォルト設定
Section titled “デフォルト設定”var DefaultSecureConfig = SecureConfig{ Skipper: DefaultSkipper, XSSProtection: "1; mode=block", ContentTypeNosniff: "nosniff", XFrameOptions: "SAMEORIGIN", HSTSPreloadEnabled: false,}Echo のセキュリティ更新 (v5.4.0 / v4.16.0)
Section titled “Echo のセキュリティ更新 (v5.4.0 / v4.16.0)”HSTS は Context#Scheme() が https の場合に送信されます。未検証の X-Forwarded-Proto: https だけでは有効になりません。公開プロキシで TLS を終端する場合はその範囲を信頼し、プロキシがヘッダーを上書きするようにしてください。