Configuración de cabeceras de seguridad y HTTPS
Refuerce su aplicación Spring en producción con cabeceras de seguridad HTTP, HSTS y HTTPS obligatorio para defenderse de ataques habituales contra el transporte y el navegador.
Configuración de cabeceras de seguridad y HTTPS es una lección gratuita de Spring Security 6 & JWT Authentication en CoddyKit. Esta es la lección 4 de 4. Puedes leer la lección completa abajo gratuitamente — luego la practicas en el navegador con un editor de código integrado y un tutor de IA 24/7. Forma parte de la ruta de aprendizaje de Spring Security 6 & JWT Authentication, y tu progreso se sincroniza en la web y la app de CoddyKit. El curso de Spring Security 6 & JWT Authentication incluye 4 lecciones en total.
Partes de esta lección aún no han sido traducidas y se muestran en inglés.
Defense at the Transport Layer
Even a well-secured backend is exposed if traffic travels unencrypted or the browser mishandles your responses. Security headers and HTTPS close these gaps at the transport and browser layer.
Why HTTPS Is Non-Negotiable
Over plain HTTP, tokens and credentials can be read or modified by anyone on the network. HTTPS encrypts traffic and verifies the server identity, and is mandatory wherever JWTs travel.
Forcing HTTPS in Spring
Use requiresChannel to redirect any HTTP request to HTTPS automatically.
http.requiresChannel(c -> c.anyRequest().requiresSecure());HSTS
HTTP Strict Transport Security tells browsers to only ever use HTTPS for your domain, preventing downgrade attacks. Spring enables it by default for secure requests.
http.headers(h -> h
.httpStrictTransportSecurity(hsts -> hsts
.maxAgeInSeconds(31536000)
.includeSubDomains(true)));Content Security Policy
A Content-Security-Policy header limits which sources of scripts and styles the browser will load, a strong defense against cross-site scripting (XSS).
http.headers(h -> h
.contentSecurityPolicy(c -> c
.policyDirectives("default-src 'self'")));Clickjacking Protection
The X-Frame-Options header stops your pages from being embedded in iframes on other sites, blocking clickjacking. Spring sets DENY by default.
http.headers(h -> h
.frameOptions(f -> f.deny()));Preventing MIME Sniffing
The X-Content-Type-Options: nosniff header stops browsers from guessing content types, which can turn an uploaded file into executable script. It is on by default in Spring Security.
Referrer Policy
The Referrer-Policy header controls how much URL information leaks to other sites when users follow links, protecting tokens or ids that might sit in URLs.
http.headers(h -> h
.referrerPolicy(r -> r.policy(
ReferrerPolicy.SAME_ORIGIN)));Disabling the Cache for Sensitive Pages
Spring adds cache-control headers to keep authenticated responses out of browser and proxy caches, so a logged-out user on a shared machine cannot hit Back to see private data.
Cookies for Tokens
If you store tokens in cookies, mark them HttpOnly (JS cannot read), Secure (HTTPS only), and SameSite to mitigate XSS and CSRF.
Cookie c = new Cookie('token', value);
c.setHttpOnly(true);
c.setSecure(true);Verifying Your Headers
After deploying, scan your site with tools like securityheaders.com or curl to confirm each header is present and correctly valued. Trust nothing until you have checked the live response.
curl -I https://yourapp.example.comQuick Check
Test your understanding of security headers.
Recap
You learned to harden the transport and browser layer:
- Force HTTPS with
requiresChanneland enable HSTS - Use CSP, X-Frame-Options, and nosniff to block XSS and clickjacking
- Set HttpOnly, Secure, SameSite on token cookies
- Verify headers on the live deployment
These headers add cheap, high-value protection in production.
Preguntas frecuentes
¿La lección «Configuración de cabeceras de seguridad y HTTPS» es gratis?
Sí — el texto completo de «Configuración de cabeceras de seguridad y HTTPS» es gratis para leer aquí en la web. Para practicarla de forma interactiva (editor de código integrado y tutor de IA 24/7) y desbloquear el resto del curso de Spring Security 6 & JWT Authentication, actualiza a CoddyKit PRO. El curso de Spring Security 6 & JWT Authentication incluye 4 lecciones en total.
¿Qué aprenderé en «Configuración de cabeceras de seguridad y HTTPS»?
Refuerce su aplicación Spring en producción con cabeceras de seguridad HTTP, HSTS y HTTPS obligatorio para defenderse de ataques habituales contra el transporte y el navegador. Practicas Spring Security 6 & JWT Authentication con código real que ejecutas directamente en el navegador, y un tutor de IA 24/7 responde tus preguntas mientras trabajas en la lección.
¿Necesito experiencia previa para empezar Spring Security 6 & JWT Authentication?
No se requiere experiencia previa. Spring Security 6 & JWT Authentication en CoddyKit está estructurado para principiantes hasta estudiantes avanzados, así que puedes empezar aquí o desde el inicio y avanzar a tu ritmo. Esta es la lección 4 de 4.
¿Cuánto tiempo toma la lección «Configuración de cabeceras de seguridad y HTTPS»?
La mayoría de las lecciones de CoddyKit toman alrededor de 5–10 minutos. Cada una es compacta e interactiva, así que avanzas constantemente y retomas exactamente por donde dejaste en la web y la app.
¿Puedo escribir y ejecutar código en esta lección de Spring Security 6 & JWT Authentication?
Sí. Cada lección de Spring Security 6 & JWT Authentication incluye un editor de código integrado, así que escribes y ejecutas código real directamente en tu navegador y obtienes retroalimentación instantánea de IA — sin configuración local necesaria.
Todas las lecciones de este curso
- Refuerzo de la seguridad en producción
- Registro y monitorización de eventos de seguridad
- Vulnerabilidades de seguridad habituales y soluciones
- Configuración de cabeceras de seguridad y HTTPS