Merge pull request #14939 from swordqiu/hotfix/qj-add-hsts-header-if-tls-enabled

fix: add HSTS (RFC 6797) header if TLS enabled
This commit is contained in:
Zexi Li
2022-09-07 10:36:17 +08:00
committed by GitHub
+6
View File
@@ -67,6 +67,8 @@ type Application struct {
idleConnsClosed chan struct{}
httpServer *http.Server
slaveHttpServer *http.Server
isTLS bool
}
const (
@@ -315,6 +317,9 @@ func (app *Application) defaultHandle(w http.ResponseWriter, r *http.Request, ri
w.Header().Set("Server", "Yunion AppServer/Go/2018.4")
w.Header().Set("X-Frame-Options", "SAMEORIGIN")
w.Header().Set("X-XSS-Protection", "1; mode=block")
if app.isTLS {
w.Header().Set("Strict-Transport-Security", "max-age=31536000; includeSubDomains")
}
isCors := app.handleCORS(w, r)
handler := app.getRoot(r.Method).Match(segs, params)
if handler != nil {
@@ -500,6 +505,7 @@ func (app *Application) ListenAndServeWithoutCleanup(addr, certFile, keyFile str
}
func (app *Application) ListenAndServeTLSWithCleanup2(addr string, certFile, keyFile string, onStop func(), isMaster bool) {
app.isTLS = true
httpSrv := app.initServer(addr)
if isMaster {
app.addDefaultHandlers()