跳转到内容

安全

Secure 中间件提供对跨站脚本(XSS)、内容类型嗅探、点击劫持、不安全连接和其他代码注入攻击的防护。

所有核心中间件都位于 middleware 包中:

import "github.com/labstack/echo/v5/middleware"
e.Use(middleware.Secure())
e := echo.New()
e.Use(middleware.SecureWithConfig(middleware.SecureConfig{
XSSProtection: "",
ContentTypeNosniff: "",
XFrameOptions: "",
HSTSMaxAge: 3600,
ContentSecurityPolicy: "default-src 'self'",
}))

SecureConfig · github.com/labstack/echo/v5@5196b9b

字段说明由英文源码注释生成。

包源码中的字段
字段类型说明源码
Skipper Skipper Skipper defines a function to skip middleware. L15
XSSProtection string XSSProtection provides protection against cross-site scripting attack (XSS) by setting the `X-XSS-Protection` header. Optional. Default value "1; mode=block". L20
ContentTypeNosniff string ContentTypeNosniff provides protection against overriding Content-Type header by setting the `X-Content-Type-Options` header. Optional. Default value "nosniff". L25
XFrameOptions string XFrameOptions can be used to indicate whether or not a browser should be allowed to render a page in a <frame>, <iframe> or <object> . Sites can use this to avoid clickjacking attacks, by ensuring that their content is not embedded into other sites.provides protection against clickjacking. Optional. Default value "SAMEORIGIN". Possible values: - "SAMEORIGIN" - The page can only be displayed in a frame on the same origin as the page itself. - "DENY" - The page cannot be displayed in a frame, regardless of the site attempting to do so. - "ALLOW-FROM uri" - The page can only be displayed in a frame on the specified origin. L37
HSTSMaxAge int HSTSMaxAge sets the `Strict-Transport-Security` header to indicate how long (in seconds) browsers should remember that this site is only to be accessed using HTTPS. This reduces your exposure to some SSL-stripping man-in-the-middle (MITM) attacks. Optional. Default value 0. L44
HSTSExcludeSubdomains bool HSTSExcludeSubdomains won't include subdomains tag in the `Strict Transport Security` header, excluding all subdomains from security policy. It has no effect unless HSTSMaxAge is set to a non-zero value. Optional. Default value false. L50
ContentSecurityPolicy string ContentSecurityPolicy sets the `Content-Security-Policy` header providing security against cross-site scripting (XSS), clickjacking and other code injection attacks resulting from execution of malicious content in the trusted web page context. Optional. Default value "". L57
CSPReportOnly bool CSPReportOnly would use the `Content-Security-Policy-Report-Only` header instead of the `Content-Security-Policy` header. This allows iterative updates of the content security policy by only reporting the violations that would have occurred instead of blocking the resource. Optional. Default value false. L64
HSTSPreloadEnabled bool HSTSPreloadEnabled will add the preload tag in the `Strict Transport Security` header, which enables the domain to be included in the HSTS preload list maintained by Chrome (and used by Firefox and Safari): https://hstspreload.org/ Optional. Default value false. L70
ReferrerPolicy string ReferrerPolicy sets the `Referrer-Policy` header providing security against leaking potentially sensitive request paths to third parties. Optional. Default value "". L75
包源码中的函数
类型源码
func Secure() echo.MiddlewareFunc L91
func SecureWithConfig(config SecureConfig) echo.MiddlewareFunc L96
var DefaultSecureConfig = SecureConfig{
Skipper: DefaultSkipper,
XSSProtection: "1; mode=block",
ContentTypeNosniff: "nosniff",
XFrameOptions: "SAMEORIGIN",
HSTSPreloadEnabled: false,
}

只有 Context#Scheme() 为 https 时才发送 HSTS,未经验证的 X-Forwarded-Proto: https 不会启用 HSTS。如果公网代理终止 TLS,请信任其地址段,并确保代理覆盖该标头。