PasteZap
🌐 日本語
無料 · アカウント不要

無料 · ネットワーク・IT インフラ

HTTP セキュリティヘッダー生成.

Nginx、Apache、Caddy、IIS、_headers、Express 向けに Content-Security-Policy、HSTS、Referrer-Policy、Permissions-Policy、クロスオリジンヘッダーを作成します。

はじめる前に

一部の技術的な操作項目は英語です。Unicode テキストに対応していますが、ファイル形式と出力言語はツールによって異なります。

技術的な制限は以下に英語で記載されています。大きなファイルを処理する前や結果を使用する前に確認してください。

CALCULATED IN YOUR BROWSER · NOTHING IS UPLOADED

Strict-Transport-Security (HSTS)

Content-Security-Policy

Other headers

Headers7

Configuration

# Inside the server { } block. A location that has its own add_header does not inherit these.
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Frame-Options "DENY" always;
server_tokens off;

Headers sent

HeaderValue
Strict-Transport-Securitymax-age=31536000; includeSubDomains
Content-Security-Policy-Report-Onlydefault-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests
X-Content-Type-Optionsnosniff
Referrer-Policystrict-origin-when-cross-origin
Permissions-Policycamera=(), microphone=(), geolocation=(), payment=(), usb=()
Cross-Origin-Opener-Policysame-origin
X-Frame-OptionsDENY
  • Test the site after deploying: a strict CSP can block scripts, fonts or embeds you rely on. The browser console names each blocked resource.
  • Only send HSTS on HTTPS responses; browsers ignore it over plain HTTP.

使い方: HTTP セキュリティヘッダー生成

データを入力するかファイルを選び、設定を調整して結果を生成します。コピーやダウンロードの前に結果を確認してください。

制限と対応形式

入力内容はお使いの端末で処理されます。

英語の技術説明

CSP sources are validated for syntax, not reachability. Test the site after deploying; a strict policy can block resources you rely on. Everything is calculated in your browser; nothing is sent or probed on the network.

Selected options are assembled into header values, CSP keywords are quoted automatically, and the list is written in each server’s syntax with the escaping it needs.

HSTS for one year, a report-only CSP, nosniff, strict-origin-when-cross-origin and disabled camera/microphone produce seven headers ready for Nginx.