nginx删除不安全的请求头

###参考https://veggiespam.com/headers/
###nginx作为反向代理

# Redirect 80 --> 443
server {
    listen 80;
    listen [::]:80;
    server_name veggiespam.com www.veggiespam.com;

    return 301 https://$host$request_uri;
}

# HTTPS proxies to local instance
server {
    listen 443;
    listen [::]:443;
    server_name veggiespam.com www.veggiespam.com

    # Put TLS configuration here

    location / {
        proxy_pass http://localhost:4567;
        proxy_pass_header Set-Cookie;
        proxy_redirect off;
        proxy_set_header Accept-Encoding '';
        proxy_set_header Referer $http_referer;
        proxy_set_header Host $host;
        proxy_http_version 1.1;
# Remove Headers begin
        proxy_hide_header X-Powered-By;
        proxy_hide_header Server;
        proxy_hide_header X-AspNetMvc-Version;
        proxy_hide_header X-AspNet-Version;
# end Remove Headers
        proxy_set_header Cookie $http_cookie;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-Host $host;
        proxy_set_header X-Forwarded-Server $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_no_cache $http_pragma $http_authorization;
        proxy_cache_bypass $http_pragma $http_authorization;
        proxy_next_upstream error timeout invalid_header http_500 http_502 http_503 http_504 http_404;
    }
}

###Apache作为反向代理

<VirtualHost *:80>
    ServerName www.veggiespam.com
    ServerAdmin evil-kitten@veggiespam.com

    ProxyRequests Off
    ProxyPreserveHost Off
    AllowEncodedSlashes On
    KeepAlive Off

    <Proxy *>
        Order deny,allow
        Allow from all
    </Proxy>

# Remove Headers begin
    Header unset X-Powered-By
    Header unset Server
    Header unset X-AspNetMvc-Version
    Header unset X-AspNet-Version
# end Remove Headers
    ProxyPass / http://localhost:5984/ example
    ProxyPassReverse / http://localhost:5984/
</VirtualHost>
  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值