Renforcer Nginx avec des en-têtes de sécurité
Ajoutez des en-têtes de sécurité HTTP dans Nginx pour vous défendre contre le détournement de clics, la détection automatique du type MIME et les attaques par injection de contenu.
Renforcer Nginx avec des en-têtes de sécurité est une leçon API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) gratuite sur CoddyKit. Ceci est la leçon 4 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway), et ta progression se synchronise sur le web et l'application CoddyKit. Le cours API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) comprend 4 leçons au total.
Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.
Headers as a Defense Layer
Beyond TLS and authentication, modern browsers honor security headers that instruct them how to behave. Nginx can inject these on every response with the add_header directive.
Preventing MIME Sniffing
X-Content-Type-Options: nosniff stops browsers from guessing a resource's type, blocking attacks that disguise a script as an image.
add_header X-Content-Type-Options "nosniff" always;Blocking Clickjacking
X-Frame-Options controls whether your site can be embedded in a frame. Use DENY or SAMEORIGIN to prevent clickjacking.
add_header X-Frame-Options "SAMEORIGIN" always;Strict Transport Security
HSTS forces browsers to use HTTPS for future visits. Set a long max-age once HTTPS is stable everywhere.
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;Content Security Policy
A Content-Security-Policy restricts where scripts, styles, and other resources may load from, mitigating cross-site scripting.
add_header Content-Security-Policy "default-src 'self'" always;Controlling the Referrer
Referrer-Policy limits how much referrer information leaks to other sites when users click outbound links.
add_header Referrer-Policy "strict-origin-when-cross-origin" always;Why the always Flag
Without always, Nginx adds the header only on successful responses (2xx, 3xx). The always flag ensures the header is present on error responses too.
add_header X-Frame-Options "DENY" always;Hiding the Nginx Version
By default Nginx reveals its version in the Server header and error pages. Turn this off to give attackers less information.
server_tokens off;The add_header Inheritance Trap
If a location block has its own add_header, it replaces all inherited headers from the parent. Re-declare needed headers in nested blocks.
# headers in http/server are dropped here
location /api {
add_header X-Content-Type-Options "nosniff" always;
}Grouping Security Headers
Keep all security headers in one include file and pull it into each server block for consistency.
# security_headers.conf
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
# server block:
include /etc/nginx/security_headers.conf;Verifying Headers
Use curl to inspect the response headers and confirm each one is present, even on error responses.
curl -I https://example.comQuick Check
Which header tells the browser to refuse loading your site inside a frame on another domain?
Recap
You hardened Nginx with browser security headers:
nosniffblocks MIME confusionX-Frame-Optionsstops clickjacking- HSTS enforces HTTPS, CSP restricts resources
- Use
alwaysand bewareadd_headerinheritance server_tokens offhides the version
These complement TLS and authentication for defense in depth.
Apprends API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) avec un tuteur IA — gratuit
Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.
- Cours
- 12
- Leçons
- 48
Questions Fréquemment Posées
La leçon « Renforcer Nginx avec des en-têtes de sécurité » est-elle gratuite ?
Oui — le texte complet de « Renforcer Nginx avec des en-têtes de sécurité » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway), passe à CoddyKit PRO. Le cours API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) comprend 4 leçons au total.
Qu'est-ce que j'apprendrai dans « Renforcer Nginx avec des en-têtes de sécurité » ?
Ajoutez des en-têtes de sécurité HTTP dans Nginx pour vous défendre contre le détournement de clics, la détection automatique du type MIME et les attaques par injection de contenu. Tu pratiques API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.
Dois-je avoir de l'expérience pour commencer API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) ?
Aucune expérience préalable n'est requise. API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 4 sur 4.
Combien de temps prend la leçon « Renforcer Nginx avec des en-têtes de sécurité » ?
La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.
Peux-tu écrire et exécuter du code dans cette leçon API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) ?
Oui. Chaque leçon API Gateway & Reverse Proxy (Nginx + Spring Cloud Gateway) inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.
Toutes les leçons de ce cours
- Sécuriser Nginx avec SSL/TLS
- HTTP/2 et optimisation de Nginx
- Authentification de base et contrôle d’accès
- Renforcer Nginx avec des en-têtes de sécurité