From 64404ea94b2f3fe9290d2819a0f400c98116b197 Mon Sep 17 00:00:00 2001 From: bjdgyc Date: Wed, 13 Dec 2023 16:50:35 +0800 Subject: [PATCH] =?UTF-8?q?=E4=BF=AE=E6=94=B9readme?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- README.md | 8 +++++++- server/pkg/utils/secure_header.go | 9 ++++++--- 2 files changed, 13 insertions(+), 4 deletions(-) diff --git a/README.md b/README.md index 0f48b70..2aad3e5 100644 --- a/README.md +++ b/README.md @@ -60,11 +60,17 @@ AnyLink 服务端仅在 CentOS 7、CentOS 8、Ubuntu 18.04、Ubuntu 20.04 测试 ### 自行编译安装 -> 需要提前安装好 golang >= 1.19 和 nodejs >= 14.x 和 yarn >= v1.22.x +> 需要提前安装好 golang >= 1.19 和 nodejs >= 16.x 和 yarn >= v1.22.x ```shell git clone https://github.com/bjdgyc/anylink.git +# 编译参考软件版本 +# go 1.20.12 +# node v16.20.2 +# yarn 1.22.19 + + cd anylink sh build.sh diff --git a/server/pkg/utils/secure_header.go b/server/pkg/utils/secure_header.go index f31dbe1..ae83774 100644 --- a/server/pkg/utils/secure_header.go +++ b/server/pkg/utils/secure_header.go @@ -2,7 +2,9 @@ package utils import "net/http" -// 设置安全的header头 +// SetSecureHeader 设置安全的header头 +// https://blog.csdn.net/liwan09/article/details/130248003 +// https://zhuanlan.zhihu.com/p/335165168 func SetSecureHeader(w http.ResponseWriter) { // Content-Length Date 默认已经存在 w.Header().Set("Server", "AnyLinkOpenSource") @@ -18,12 +20,13 @@ func SetSecureHeader(w http.ResponseWriter) { w.Header().Set("X-Download-Options", "noopen") w.Header().Set("Content-Security-Policy", "default-src 'self' 'unsafe-inline' 'unsafe-eval' data: blob:; frame-ancestors 'self'; base-uri 'self'; block-all-mixed-content") w.Header().Set("X-Permitted-Cross-Domain-Policies", "none") - w.Header().Set("Referrer-Policy", "no-referrer") + w.Header().Set("Referrer-Policy", "same-origin") w.Header().Set("Cross-Origin-Embedder-Policy", "require-corp") w.Header().Set("Cross-Origin-Opener-Policy", "same-origin") w.Header().Set("Cross-Origin-Resource-Policy", "same-origin") - w.Header().Set("X-XSS-Protection", "1") + w.Header().Set("X-XSS-Protection", "1;mode=block") w.Header().Set("Strict-Transport-Security", "max-age=31536000; includeSubDomains") // w.Header().Set("Clear-Site-Data", "cache,cookies,storage") + }