Skip to content

Secure

Secure middleware provides protection against cross-site scripting (XSS), content type sniffing, clickjacking, insecure connections, and other code injection attacks.

All core middleware lives in the middleware package:

import "github.com/labstack/echo/v5/middleware"
e.Use(middleware.Secure())

HSTS is sent when Context#Scheme() is https. A raw X-Forwarded-Proto: https header from an untrusted client does not enable HSTS. If a public proxy terminates TLS, trust its address range and make sure it overwrites X-Forwarded-Proto; otherwise HSTS may be missing.

e := echo.New()
e.Use(middleware.SecureWithConfig(middleware.SecureConfig{
XSSProtection: "",
ContentTypeNosniff: "",
XFrameOptions: "",
HSTSMaxAge: 3600,
ContentSecurityPolicy: "default-src 'self'",
}))

SecureConfig · github.com/labstack/echo/v5@5196b9b

Fields from package source
FieldTypeDescriptionSource
Skipper Skipper Skipper defines a function to skip middleware. L15
XSSProtection string XSSProtection provides protection against cross-site scripting attack (XSS) by setting the `X-XSS-Protection` header. Optional. Default value "1; mode=block". L20
ContentTypeNosniff string ContentTypeNosniff provides protection against overriding Content-Type header by setting the `X-Content-Type-Options` header. Optional. Default value "nosniff". L25
XFrameOptions string XFrameOptions can be used to indicate whether or not a browser should be allowed to render a page in a <frame>, <iframe> or <object> . Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.provides protection against clickjacking. Optional. Default value "SAMEORIGIN". Possible values: - "SAMEORIGIN" - The page can only be displayed in a frame on the same origin as the page itself. - "DENY" - The page cannot be displayed in a frame, regardless of the site attempting to do so. - "ALLOW-FROM uri" - The page can only be displayed in a frame on the specified origin. L37
HSTSMaxAge int HSTSMaxAge sets the `Strict-Transport-Security` header to indicate how long (in seconds) browsers should remember that this site is only to be accessed using HTTPS. This reduces your exposure to some SSL-stripping man-in-the-middle (MITM) attacks. Optional. Default value 0. L44
HSTSExcludeSubdomains bool HSTSExcludeSubdomains won't include subdomains tag in the `Strict Transport Security` header, excluding all subdomains from security policy. It has no effect unless HSTSMaxAge is set to a non-zero value. Optional. Default value false. L50
ContentSecurityPolicy string ContentSecurityPolicy sets the `Content-Security-Policy` header providing security against cross-site scripting (XSS), clickjacking and other code injection attacks resulting from execution of malicious content in the trusted web page context. Optional. Default value "". L57
CSPReportOnly bool CSPReportOnly would use the `Content-Security-Policy-Report-Only` header instead of the `Content-Security-Policy` header. This allows iterative updates of the content security policy by only reporting the violations that would have occurred instead of blocking the resource. Optional. Default value false. L64
HSTSPreloadEnabled bool HSTSPreloadEnabled will add the preload tag in the `Strict Transport Security` header, which enables the domain to be included in the HSTS preload list maintained by Chrome (and used by Firefox and Safari): https://hstspreload.org/ Optional. Default value false. L70
ReferrerPolicy string ReferrerPolicy sets the `Referrer-Policy` header providing security against leaking potentially sensitive request paths to third parties. Optional. Default value "". L75
Functions from package source
TypeSource
func Secure() echo.MiddlewareFunc L91
func SecureWithConfig(config SecureConfig) echo.MiddlewareFunc L96
var DefaultSecureConfig = SecureConfig{
Skipper: DefaultSkipper,
XSSProtection: "1; mode=block",
ContentTypeNosniff: "nosniff",
XFrameOptions: "SAMEORIGIN",
HSTSPreloadEnabled: false,
}