0Pricing
Django Academy · 课时

HTTPS、HSTS 与安全 Cookie

强制使用加密的安全连接

HTTPS、HSTS 与安全 Cookie 是 CoddyKit 上的免费 Django Academy 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Django Academy 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Django Academy 课程共包含 4 节课。

本课时的部分内容尚未翻译,以英文显示。

Why HTTPS Matters

Plain HTTP sends passwords and cookies as readable text anyone on the network can grab. HTTPS encrypts the whole conversation between browser and server. 🔐

Redirect HTTP to HTTPS

Turn on SECURE_SSL_REDIRECT so Django bounces any plain HTTP request to its HTTPS version automatically. No more accidental insecure pages.

SECURE_SSL_REDIRECT = True

Trust the Proxy Header

Behind Nginx, Django needs to know the request arrived over TLS. The SECURE_PROXY_SSL_HEADER tells it which header to trust for that.

SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")

What HSTS Is

HSTS tells browsers to only ever talk to your site over HTTPS for a set time. Even typing http will be upgraded before any request leaves the browser.

Enable HSTS Carefully

Set SECURE_HSTS_SECONDS to enable HSTS. Start small while testing, since browsers will remember it and refuse plain HTTP until it expires.

SECURE_HSTS_SECONDS = 31536000

Extend HSTS Reach

Cover every subdomain and qualify for preload lists with two extra flags. They make HSTS apply broadly and let browsers ship it built in.

SECURE_HSTS_INCLUDE_SUBDOMAINS = True
SECURE_HSTS_PRELOAD = True

Cookies Travel With Requests

Your session and CSRF cookies authenticate users. If they leak over HTTP, an attacker can hijack the session, so they need protection flags too.

Secure the Session Cookie

Set SESSION_COOKIE_SECURE to True so the session cookie is only ever sent over HTTPS, never on an unencrypted connection.

SESSION_COOKIE_SECURE = True

Secure the CSRF Cookie

Do the same for CSRF protection. With CSRF_COOKIE_SECURE on, the token cookie also refuses to ride along over plain HTTP.

CSRF_COOKIE_SECURE = True

Block JavaScript Access

The HttpOnly flag hides the session cookie from JavaScript, so a cross-site script cannot read and steal it. Django sets it on sessions by default.

SESSION_COOKIE_HTTPONLY = True

Limit Cookie Sharing

The SameSite attribute stops cookies from being sent on cross-site requests, adding a second layer of CSRF defense. Django defaults it to Lax for you.

SESSION_COOKIE_SAMESITE = "Lax"

Quick Check

Let us see if the HSTS idea stuck.

Recap: Encrypted End to End

You forced HTTPS, taught browsers to remember it with HSTS, and marked your cookies secure and HttpOnly. Traffic and sessions are now encrypted end to end. ✨

常见问题解答

「HTTPS、HSTS 与安全 Cookie」课时是免费的吗?

是的 — 「HTTPS、HSTS 与安全 Cookie」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Django Academy 课程的其余内容,请升级到 CoddyKit PRO。 Django Academy 课程共包含 4 节课。

「HTTPS、HSTS 与安全 Cookie」这节课中我会学到什么?

强制使用加密的安全连接 你通过在浏览器中直接运行的动手代码来练习 Django Academy,全天候 AI 导师会在你学习这节课的过程中回答你的问题。

学习 Django Academy 需要有经验吗?

无需任何先前经验。CoddyKit 上的 Django Academy 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。

「HTTPS、HSTS 与安全 Cookie」课时需要多长时间?

大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。

我能在这节 Django Academy 课中编写并运行代码吗?

能。每节 Django Academy 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。

此课程中的所有课时

  1. DEBUG、SECRET_KEY 与 ALLOWED_HOSTS
  2. HTTPS、HSTS 与安全 Cookie
  3. XSS、CSRF 与 SQL 注入防护
  4. 执行部署检查清单
← 返回 Django Academy