免费 · 网络与 IT 基础设施
HTTP 安全响应头生成器.
为 Nginx、Apache、Caddy、IIS、_headers 和 Express 生成 Content-Security-Policy、HSTS、Referrer-Policy、Permissions-Policy 和跨源响应头。
Strict-Transport-Security (HSTS)
Content-Security-Policy
Other headers
Report-only mode does not block anything. Watch the browser console or reports, then switch to Enforce.
Configuration
# Inside the server { } block. A location that has its own add_header does not inherit these.
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
add_header Content-Security-Policy-Report-Only "default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests" always;
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()" always;
add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header X-Frame-Options "DENY" always;
server_tokens off;Headers sent
| Header | Value |
|---|---|
| Strict-Transport-Security | max-age=31536000; includeSubDomains |
| Content-Security-Policy-Report-Only | default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; font-src 'self'; connect-src 'self'; frame-src 'none'; object-src 'none'; base-uri 'self'; form-action 'self'; frame-ancestors 'none'; upgrade-insecure-requests |
| X-Content-Type-Options | nosniff |
| Referrer-Policy | strict-origin-when-cross-origin |
| Permissions-Policy | camera=(), microphone=(), geolocation=(), payment=(), usb=() |
| Cross-Origin-Opener-Policy | same-origin |
| X-Frame-Options | DENY |
- Test the site after deploying: a strict CSP can block scripts, fonts or embeds you rely on. The browser console names each blocked resource.
- Only send HSTS on HTTPS responses; browsers ignore it over plain HTTP.
使用方法: HTTP 安全响应头生成器
输入数据或选择文件,调整设置并生成结果。复制或下载之前,请检查结果。
限制与支持格式
输入内容在您的设备上处理。
英语技术说明
CSP sources are validated for syntax, not reachability. Test the site after deploying; a strict policy can block resources you rely on. Everything is calculated in your browser; nothing is sent or probed on the network.
Selected options are assembled into header values, CSP keywords are quoted automatically, and the list is written in each server’s syntax with the escaping it needs.
HSTS for one year, a report-only CSP, nosniff, strict-origin-when-cross-origin and disabled camera/microphone produce seven headers ready for Nginx.