From 7a0a3a47f7a4104d0e14e1737245267210256948 Mon Sep 17 00:00:00 2001 From: Qiu Jian Date: Wed, 7 Sep 2022 07:48:41 +0800 Subject: [PATCH] fix: add HSTS (RFC 6797) header if TLS enabled https://www.tenable.com/plugins/nessus/142960 --- pkg/appsrv/appsrv.go | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/pkg/appsrv/appsrv.go b/pkg/appsrv/appsrv.go index ad51816a76..1448ecd990 100644 --- a/pkg/appsrv/appsrv.go +++ b/pkg/appsrv/appsrv.go @@ -67,6 +67,8 @@ type Application struct { idleConnsClosed chan struct{} httpServer *http.Server slaveHttpServer *http.Server + + isTLS bool } const ( @@ -315,6 +317,9 @@ func (app *Application) defaultHandle(w http.ResponseWriter, r *http.Request, ri w.Header().Set("Server", "Yunion AppServer/Go/2018.4") w.Header().Set("X-Frame-Options", "SAMEORIGIN") w.Header().Set("X-XSS-Protection", "1; mode=block") + if app.isTLS { + w.Header().Set("Strict-Transport-Security", "max-age=31536000; includeSubDomains") + } isCors := app.handleCORS(w, r) handler := app.getRoot(r.Method).Match(segs, params) if handler != nil { @@ -500,6 +505,7 @@ func (app *Application) ListenAndServeWithoutCleanup(addr, certFile, keyFile str } func (app *Application) ListenAndServeTLSWithCleanup2(addr string, certFile, keyFile string, onStop func(), isMaster bool) { + app.isTLS = true httpSrv := app.initServer(addr) if isMaster { app.addDefaultHandlers()