Spring Security 6 & JWT Authentication · Lekcja

Konfigurowanie nagłówków bezpieczeństwa i HTTPS

Wzmocnij produkcyjną aplikację Spring za pomocą nagłówków bezpieczeństwa HTTP, HSTS i wymuszonego HTTPS, aby chronić ją przed typowymi atakami na warstwę transportową i przeglądarkę.

Lekcja 4 z 413 kroki

Konfigurowanie nagłówków bezpieczeństwa i HTTPS to bezpłatna lekcja Spring Security 6 & JWT Authentication na CoddyKit. To lekcja 4 z 4. Możesz przeczytać całą lekcję poniżej za darmo — a potem ćwiczyć ją interaktywnie w przeglądarce z wbudowanym edytorem kodu i tutorem AI dostępnym 24/7. To część ścieżki edukacyjnej Spring Security 6 & JWT Authentication, a Twój postęp synchronizuje się między webem a aplikacją CoddyKit. Kurs Spring Security 6 & JWT Authentication zawiera 4 lekcji w sumie.

Części tej lekcji nie zostały jeszcze przetłumaczone i są wyświetlane po angielsku.

Defense at the Transport Layer

Even a well-secured backend is exposed if traffic travels unencrypted or the browser mishandles your responses. Security headers and HTTPS close these gaps at the transport and browser layer.

Why HTTPS Is Non-Negotiable

Over plain HTTP, tokens and credentials can be read or modified by anyone on the network. HTTPS encrypts traffic and verifies the server identity, and is mandatory wherever JWTs travel.

Forcing HTTPS in Spring

Use requiresChannel to redirect any HTTP request to HTTPS automatically.

http.requiresChannel(c -> c.anyRequest().requiresSecure());

HSTS

HTTP Strict Transport Security tells browsers to only ever use HTTPS for your domain, preventing downgrade attacks. Spring enables it by default for secure requests.

http.headers(h -> h
    .httpStrictTransportSecurity(hsts -> hsts
        .maxAgeInSeconds(31536000)
        .includeSubDomains(true)));

Content Security Policy

A Content-Security-Policy header limits which sources of scripts and styles the browser will load, a strong defense against cross-site scripting (XSS).

http.headers(h -> h
    .contentSecurityPolicy(c -> c
        .policyDirectives("default-src 'self'")));

Clickjacking Protection

The X-Frame-Options header stops your pages from being embedded in iframes on other sites, blocking clickjacking. Spring sets DENY by default.

http.headers(h -> h
    .frameOptions(f -> f.deny()));

Preventing MIME Sniffing

The X-Content-Type-Options: nosniff header stops browsers from guessing content types, which can turn an uploaded file into executable script. It is on by default in Spring Security.

Referrer Policy

The Referrer-Policy header controls how much URL information leaks to other sites when users follow links, protecting tokens or ids that might sit in URLs.

http.headers(h -> h
    .referrerPolicy(r -> r.policy(
        ReferrerPolicy.SAME_ORIGIN)));

Disabling the Cache for Sensitive Pages

Spring adds cache-control headers to keep authenticated responses out of browser and proxy caches, so a logged-out user on a shared machine cannot hit Back to see private data.

Cookies for Tokens

If you store tokens in cookies, mark them HttpOnly (JS cannot read), Secure (HTTPS only), and SameSite to mitigate XSS and CSRF.

Cookie c = new Cookie('token', value);
c.setHttpOnly(true);
c.setSecure(true);

Verifying Your Headers

After deploying, scan your site with tools like securityheaders.com or curl to confirm each header is present and correctly valued. Trust nothing until you have checked the live response.

curl -I https://yourapp.example.com

Quick Check

Test your understanding of security headers.

Recap

You learned to harden the transport and browser layer:

  • Force HTTPS with requiresChannel and enable HSTS
  • Use CSP, X-Frame-Options, and nosniff to block XSS and clickjacking
  • Set HttpOnly, Secure, SameSite on token cookies
  • Verify headers on the live deployment

These headers add cheap, high-value protection in production.

Bezpłatny start

Ucz się Java dzięki korepetycjom AI — za darmo

Pisz i uruchamiaj kod w przeglądarce, otrzymuj natychmiastową pomoc od korepetytora AI dostępnego 24/7 i kontynuuj naukę w sieci lub w aplikacji.

Kursy
12
Lekcje
48

Często zadawane pytania

Czy lekcja „Konfigurowanie nagłówków bezpieczeństwa i HTTPS” jest bezpłatna?

Tak — pełny tekst „Konfigurowanie nagłówków bezpieczeństwa i HTTPS” jest dostępny za darmo tutaj w sieci. Aby ćwiczyć ją interaktywnie (wbudowany edytor kodu i tutor AI dostępny 24/7) i odblokować resztę kursu Spring Security 6 & JWT Authentication, przejdź na CoddyKit PRO. Kurs Spring Security 6 & JWT Authentication zawiera 4 lekcji w sumie.

Co nauczysz się w „Konfigurowanie nagłówków bezpieczeństwa i HTTPS”?

Wzmocnij produkcyjną aplikację Spring za pomocą nagłówków bezpieczeństwa HTTP, HSTS i wymuszonego HTTPS, aby chronić ją przed typowymi atakami na warstwę transportową i przeglądarkę. Ćwiczysz Spring Security 6 & JWT Authentication z praktycznym kodem, który uruchamiasz bezpośrednio w przeglądarce, a tutor AI dostępny 24/7 odpowiada na Twoje pytania podczas pracy nad lekcją.

Czy potrzebuję doświadczenia, aby zacząć Spring Security 6 & JWT Authentication?

Nie wymagamy żadnego doświadczenia. Spring Security 6 & JWT Authentication w CoddyKit jest strukturyzowany dla początkujących i zaawansowanych użytkowników, więc możesz zacząć tutaj lub od początku i uczyć się w swoim tempie. To lekcja 4 z 4.

Ile czasu zajmuje lekcja „Konfigurowanie nagłówków bezpieczeństwa i HTTPS”?

Większość lekcji CoddyKit trwa około 5–10 minut. Każda lekcja to mały, interaktywny krok, dzięki czemu robisz systematyczne postępy i zawsze wracasz dokładnie do tego samego miejsca — na webie i w aplikacji.

Czy mogę pisać i uruchamiać kod w tej lekcji Spring Security 6 & JWT Authentication?

Tak. Każda lekcja Spring Security 6 & JWT Authentication zawiera wbudowany edytor kodu, więc piszesz i uruchamiasz prawdziwy kod bezpośrednio w przeglądarce i od razu otrzymujesz sprzężenie zwrotne od AI — bez konfiguracji na komputerze.

Wszystkie lekcje w tym kursie

  1. Wzmacnianie zabezpieczeń na produkcji
  2. Logowanie i monitorowanie zdarzeń bezpieczeństwa
  3. Typowe luki w zabezpieczeniach i poprawki
  4. Konfigurowanie nagłówków bezpieczeństwa i HTTPS
← Powrót do Spring Security 6 & JWT Authentication