fix: 添加 HSTS 响应头
- SecurityHeaders 中间件增加 Strict-Transport-Security 头 - 仅在 release 模式下启用,避免开发环境 localhost 证书问题
This commit is contained in:
@ -4,6 +4,8 @@ import (
|
||||
"crypto/rand"
|
||||
"encoding/base64"
|
||||
|
||||
"metazone.cc/metalab/internal/config"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
)
|
||||
|
||||
@ -44,6 +46,11 @@ func SecurityHeaders() gin.HandlerFunc {
|
||||
// 引用策略
|
||||
c.Header("Referrer-Policy", "strict-origin-when-cross-origin")
|
||||
|
||||
// HSTS:仅在 release 模式启用,避免开发环境 localhost 证书问题
|
||||
if config.App != nil && config.App.Server.Mode == "release" {
|
||||
c.Header("Strict-Transport-Security", "max-age=31536000; includeSubDomains; preload")
|
||||
}
|
||||
|
||||
c.Next()
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user