瀏覽代碼

加入Strict-Transport-Security攻击防御

xusl 1 年之前
父節點
當前提交
1c9c802f92
共有 1 個文件被更改,包括 1 次插入0 次删除
  1. 1 0
      backend/src/main/java/com/jiayue/ssi/filter/InterfaceLimitFilter.java

+ 1 - 0
backend/src/main/java/com/jiayue/ssi/filter/InterfaceLimitFilter.java

@@ -37,6 +37,7 @@ public class InterfaceLimitFilter extends OncePerRequestFilter {
     @Override
     protected void doFilterInternal(HttpServletRequest request, HttpServletResponse response, FilterChain filterChain)
         throws ServletException, IOException {
+        response.setHeader("Strict-Transport-Security", "max-age=31536; includeSubDomains");
         checkIp(request,response,filterChain);
     }