コンテンツにスキップ

セキュア

Secure ミドルウェアは、クロスサイトスクリプティング(XSS)、コンテンツタイプスニッフィング、 クリックジャッキング、安全でない接続、その他のコードインジェクション攻撃への防御を提供します。

すべてのコアミドルウェアは middleware パッケージに含まれています:

import "github.com/labstack/echo/v5/middleware"
e.Use(middleware.Secure())
e := echo.New()
e.Use(middleware.SecureWithConfig(middleware.SecureConfig{
XSSProtection: "",
ContentTypeNosniff: "",
XFrameOptions: "",
HSTSMaxAge: 3600,
ContentSecurityPolicy: "default-src 'self'",
}))

SecureConfig · github.com/labstack/echo/v5@5196b9b

フィールドの説明は英語のソースコードのコメントから生成されています。

パッケージのソースコードのフィールド
フィールド型説明ソース
Skipper Skipper Skipper defines a function to skip middleware. L15
XSSProtection string XSSProtection provides protection against cross-site scripting attack (XSS) by setting the `X-XSS-Protection` header. Optional. Default value "1; mode=block". L20
ContentTypeNosniff string ContentTypeNosniff provides protection against overriding Content-Type header by setting the `X-Content-Type-Options` header. Optional. Default value "nosniff". L25
XFrameOptions string XFrameOptions can be used to indicate whether or not a browser should be allowed to render a page in a <frame>, <iframe> or <object> . Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.provides protection against clickjacking. Optional. Default value "SAMEORIGIN". Possible values: - "SAMEORIGIN" - The page can only be displayed in a frame on the same origin as the page itself. - "DENY" - The page cannot be displayed in a frame, regardless of the site attempting to do so. - "ALLOW-FROM uri" - The page can only be displayed in a frame on the specified origin. L37
HSTSMaxAge int HSTSMaxAge sets the `Strict-Transport-Security` header to indicate how long (in seconds) browsers should remember that this site is only to be accessed using HTTPS. This reduces your exposure to some SSL-stripping man-in-the-middle (MITM) attacks. Optional. Default value 0. L44
HSTSExcludeSubdomains bool HSTSExcludeSubdomains won't include subdomains tag in the `Strict Transport Security` header, excluding all subdomains from security policy. It has no effect unless HSTSMaxAge is set to a non-zero value. Optional. Default value false. L50
ContentSecurityPolicy string ContentSecurityPolicy sets the `Content-Security-Policy` header providing security against cross-site scripting (XSS), clickjacking and other code injection attacks resulting from execution of malicious content in the trusted web page context. Optional. Default value "". L57
CSPReportOnly bool CSPReportOnly would use the `Content-Security-Policy-Report-Only` header instead of the `Content-Security-Policy` header. This allows iterative updates of the content security policy by only reporting the violations that would have occurred instead of blocking the resource. Optional. Default value false. L64
HSTSPreloadEnabled bool HSTSPreloadEnabled will add the preload tag in the `Strict Transport Security` header, which enables the domain to be included in the HSTS preload list maintained by Chrome (and used by Firefox and Safari): https://hstspreload.org/ Optional. Default value false. L70
ReferrerPolicy string ReferrerPolicy sets the `Referrer-Policy` header providing security against leaking potentially sensitive request paths to third parties. Optional. Default value "". L75
パッケージのソースコードの関数
型ソース
func Secure() echo.MiddlewareFunc L91
func SecureWithConfig(config SecureConfig) echo.MiddlewareFunc L96
var DefaultSecureConfig = SecureConfig{
Skipper: DefaultSkipper,
XSSProtection: "1; mode=block",
ContentTypeNosniff: "nosniff",
XFrameOptions: "SAMEORIGIN",
HSTSPreloadEnabled: false,
}

Echo のセキュリティ更新 (v5.4.0 / v4.16.0)

Section titled “Echo のセキュリティ更新 (v5.4.0 / v4.16.0)”

HSTS は Context#Scheme() が https の場合に送信されます。未検証の X-Forwarded-Proto: https だけでは有効になりません。公開プロキシで TLS を終端する場合はその範囲を信頼し、プロキシがヘッダーを上書きするようにしてください。