pub struct SecurityHeadersConfig {
pub enabled: bool,
pub hsts: String,
pub content_type_options: String,
pub referrer_policy: String,
pub frame_options: String,
pub csp: String,
pub extra: HashMap<String, String>,
}Expand description
Security response headers the proxy adds to every response it returns —
add-if-absent, so a backend that sets its own Content-Security-Policy,
X-Frame-Options, Strict-Transport-Security, etc. is never overridden
(pass-through-plus-defaults, as Traefik/Caddy do). HSTS is applied only to
HTTPS responses. The defaults are deliberately non-breaking; X-Frame-Options
and CSP are off by default (they break iframe-embedded apps and most apps
respectively) and are opt-in here or per app.
Fields§
§enabled: boolMaster switch. Default true.
hsts: StringStrict-Transport-Security value (HTTPS responses only). Empty disables
HSTS. Default max-age=31536000 (1y, no includeSubDomains/preload).
content_type_options: StringX-Content-Type-Options value. Empty disables. Default nosniff.
referrer_policy: StringReferrer-Policy value. Empty disables. Default
strict-origin-when-cross-origin.
frame_options: StringX-Frame-Options value. Empty (default) = off — leave it to apps, since
SAMEORIGIN/DENY break services meant to be embedded in an iframe.
csp: StringContent-Security-Policy value. Empty (default) = off — a blanket CSP
breaks most apps; set per app instead.
extra: HashMap<String, String>Arbitrary extra response headers to add-if-absent (name → value).
Trait Implementations§
Source§impl Clone for SecurityHeadersConfig
impl Clone for SecurityHeadersConfig
Source§fn clone(&self) -> SecurityHeadersConfig
fn clone(&self) -> SecurityHeadersConfig
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more