Ver Fonte

加入Strict-Transport-Security攻击防御

xusl há 1 ano atrás
pai
commit
1c9c802f92

+ 1 - 0
backend/src/main/java/com/jiayue/ssi/filter/InterfaceLimitFilter.java

@@ -37,6 +37,7 @@ public class InterfaceLimitFilter extends OncePerRequestFilter {
     @Override
     protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain)
         throws ServletException, IOException {
+        response.setHeader("Strict-Transport-Security", "max-age=31536; includeSubDomains");
         checkIp(request,response,filterChain);
     }