HeaderWriterFilter

์„ธ์„ธํ•˜๊ฒŒ ๋‹ค ์ฐพ์•„๋ณด๊ธฐ์—” ์‹œ๊ฐ„์ด ๋„ˆ๋ฌด ์˜ค๋ž˜๊ฑธ๋ฆด ๊ฒƒ ๊ฐ™์€๋ฐ ๊ทธ๋ž˜๋„ ์‹œํ๋ฆฌํ‹ฐ๊ฐ€ ์ด์ •๋„๊นŒ์ง€ ๊ธฐ๋Šฅํ•ด์ค€๋‹ค๋Š” ์ฐจ์›์—์„œ ์ธ์ง€ํ• ๋งŒํ•œ ํ•„ํ„ฐ์ธ ๊ฒƒ ๊ฐ™์•„์„œ ๊ฐ•์˜ ์ž๋ฃŒ๋ฅผ ๊ทธ๋Œ€๋กœ ์˜ฎ๊ธด๋‹ค.

HeaderWriterFilter ์‘๋‹ต ํ—ค๋”์— ์‹œํ๋ฆฌํ‹ฐ ๊ด€๋ จ ํ—ค๋”๋ฅผ ์ถ”๊ฐ€ํ•ด์ฃผ๋Š” ํ•„ํ„ฐ

  • XContentTypeOptionsHeaderWriter: ๋งˆ์ž„ ํƒ€์ž… ์Šค๋‹ˆํ•‘ ๋ฐฉ์–ด.

  • XXssProtectionHeaderWriter: ๋ธŒ๋ผ์šฐ์ €์— ๋‚ด์žฅ๋œ XSS ํ•„ํ„ฐ ์ ์šฉ.

  • CacheControlHeadersWriter: ์บ์‹œ ํžˆ์Šคํ† ๋ฆฌ ์ทจ์•ฝ์  ๋ฐฉ์–ด.

  • HstsHeaderWriter: HTTPS๋กœ๋งŒ ์†Œํ†ตํ•˜๋„๋ก ๊ฐ•์ œ.

  • XFrameOptionsHeaderWriter: clickjacking ๋ฐฉ์–ด.

๋‚ด๊ฐ€ ์š”์ฒญํ•˜๊ณ  ๋ฐ›์€ ๊ฒƒ(์˜๋„์ ์œผ๋กœ ์ž˜๋ชป๋œ ํ† ํฐ ๋ณด๋ƒˆ๋˜ ๊ฒƒ)

HTTP/1.1 401 
X-Content-Type-Options: nosniff
X-XSS-Protection: 0
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
Content-Type: application/json;charset=UTF-8
Content-Length: 13
Date: Thu, 15 Jun 2023 11:54:14 GMT
Keep-Alive: timeout=60
Connection: keep-alive

๊ฐ•์˜์ž๋ฃŒ ๋‚ด ์ƒ˜ํ”Œ

Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Content-Language: en-US
Content-Type: text/html;charset=UTF-8
Date: Sun, 04 Aug 2019 16:25:10 GMT
Expires: 0
Pragma: no-cache
Transfer-Encoding: chunked
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
X-XSS-Protection: 1; mode=block

Last updated