本文摘要至 HTTP 安全最佳实践 (很不错的一篇文章 建议细看)
以下是对 GitHub HTTP安全简单罗列~
1、全站https
2、HSTS(HTTP Strict Transport Security)
![](https://img.haomeiwen.com/i328300/7c8a000c6a8b31b3.png)
扩展阅读:HTTP Strict Transport Security | MDN
3、HPKP(HTTP Public-Key Pinning)
![](https://img.haomeiwen.com/i328300/1dac39e2ca0bcf93.png)
扩展阅读:HTTP Public Key Pinning 介绍
4、CSP(Content Security Policy)
![](https://img.haomeiwen.com/i328300/99e2dfb1042446e4.png)
扩展阅读: Content Security Policy 介绍
Content Security Policy Level 2 介绍
5、X-Frame-Options
![](https://img.haomeiwen.com/i328300/a5fff634e57766eb.png)
扩展阅读:X-Frame-Options 响应头
6、浏览器都内建XSS 保护
![](https://img.haomeiwen.com/i328300/21bd82ca1ac86ddd.png)
扩展阅读:X-XSS-Protection
7、Content Type Options
![](https://img.haomeiwen.com/i328300/699e1d500652f724.png)
扩展阅读:X-Content-Type-Options
8、SRI(Subresource Integrity)
![](https://img.haomeiwen.com/i328300/934f76ec767ad954.png)
扩展阅读:Subresource Integrity 介绍
9、消除 Server Banner
![](https://img.haomeiwen.com/i328300/633d45ee80b13f3c.png)
10、Cookie 安全 (secure 和 httponly)
![](https://img.haomeiwen.com/i328300/4581276b2a46e638.png)
网友评论