HTTPS、HSTS 与安全 Cookie
强制使用加密的安全连接
HTTPS、HSTS 与安全 Cookie 是 CoddyKit 上的免费 Django Academy 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Django Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Django Academy 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
Why HTTPS Matters
Plain HTTP sends passwords and cookies as readable text anyone on the network can grab. HTTPS encrypts the whole conversation between browser and server. 🔐
Redirect HTTP to HTTPS
Turn on SECURE_SSL_REDIRECT so Django bounces any plain HTTP request to its HTTPS version automatically. No more accidental insecure pages.
SECURE_SSL_REDIRECT = TrueTrust the Proxy Header
Behind Nginx, Django needs to know the request arrived over TLS. The SECURE_PROXY_SSL_HEADER tells it which header to trust for that.
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")What HSTS Is
HSTS tells browsers to only ever talk to your site over HTTPS for a set time. Even typing http will be upgraded before any request leaves the browser.
Enable HSTS Carefully
Set SECURE_HSTS_SECONDS to enable HSTS. Start small while testing, since browsers will remember it and refuse plain HTTP until it expires.
SECURE_HSTS_SECONDS = 31536000Extend HSTS Reach
Cover every subdomain and qualify for preload lists with two extra flags. They make HSTS apply broadly and let browsers ship it built in.
SECURE_HSTS_INCLUDE_SUBDOMAINS = True
SECURE_HSTS_PRELOAD = TrueCookies Travel With Requests
Your session and CSRF cookies authenticate users. If they leak over HTTP, an attacker can hijack the session, so they need protection flags too.
Secure the Session Cookie
Set SESSION_COOKIE_SECURE to True so the session cookie is only ever sent over HTTPS, never on an unencrypted connection.
SESSION_COOKIE_SECURE = TrueSecure the CSRF Cookie
Do the same for CSRF protection. With CSRF_COOKIE_SECURE on, the token cookie also refuses to ride along over plain HTTP.
CSRF_COOKIE_SECURE = TrueBlock JavaScript Access
The HttpOnly flag hides the session cookie from JavaScript, so a cross-site script cannot read and steal it. Django sets it on sessions by default.
SESSION_COOKIE_HTTPONLY = TrueLimit Cookie Sharing
The SameSite attribute stops cookies from being sent on cross-site requests, adding a second layer of CSRF defense. Django defaults it to Lax for you.
SESSION_COOKIE_SAMESITE = "Lax"Quick Check
Let us see if the HSTS idea stuck.
Recap: Encrypted End to End
You forced HTTPS, taught browsers to remember it with HSTS, and marked your cookies secure and HttpOnly. Traffic and sessions are now encrypted end to end. ✨
常见问题解答
「HTTPS、HSTS 与安全 Cookie」课时是免费的吗?
是的 — 「HTTPS、HSTS 与安全 Cookie」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Django Academy 课程的其余内容,请升级到 CoddyKit PRO。 Django Academy 课程共包含 4 节课。
「HTTPS、HSTS 与安全 Cookie」这节课中我会学到什么?
强制使用加密的安全连接 你通过在浏览器中直接运行的动手代码来练习 Django Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Django Academy 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Django Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。
「HTTPS、HSTS 与安全 Cookie」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Django Academy 课中编写并运行代码吗?
能。每节 Django Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- DEBUG、SECRET_KEY 与 ALLOWED_HOSTS
- HTTPS、HSTS 与安全 Cookie
- XSS、CSRF 与 SQL 注入防护
- 执行部署检查清单