You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET8 Azure Functions如何隐藏响应头中的Kestrel服务器信息?

解决Azure Functions隐藏响应头中服务器详情的问题

你尝试的几种方法无效,核心原因是Azure Functions的运行架构和普通Web应用不同——请求会先经过Functions Runtime的网关层,部分配置会被覆盖,或者需要针对Functions的模型做适配。以下是分场景的有效解决方案:

一、针对隔离进程模型(Isolated Worker,.NET 6+)

在Program.cs中通过配置Functions Worker中间件移除Server头,同时确保Kestrel的设置生效:

var host = new HostBuilder()
    .ConfigureFunctionsWorkerDefaults(app =>
    {
        // 添加中间件移除响应头的Server字段
        app.Use(async (context, next) =>
        {
            await next();
            if (context.Response.Headers.ContainsKey("Server"))
            {
                context.Response.Headers.Remove("Server");
            }
        });
    })
    .ConfigureWebHostDefaults(webBuilder =>
    {
        // 禁用Kestrel自身的Server头
        webBuilder.UseKestrel(options => options.AddServerHeader = false);
    })
    .Build();

host.Run();

二、针对In-Process进程模型(.NET 6+)

通过自定义过滤器或StartupFilter来移除Server头:

方法1:使用ActionFilter

创建Startup.cs并配置过滤器:

using Microsoft.AspNetCore.Mvc.Filters;
using Microsoft.Azure.Functions.Extensions.DependencyInjection;
using Microsoft.Extensions.DependencyInjection;

[assembly: FunctionsStartup(typeof(YourNamespace.Startup))]
namespace YourNamespace
{
    public class Startup : FunctionsStartup
    {
        public override void Configure(IFunctionsHostBuilder builder)
        {
            builder.Services.AddMvc(options =>
            {
                options.Filters.Add(new RemoveServerHeaderFilter());
            });
        }
    }

    public class RemoveServerHeaderFilter : IActionFilter
    {
        public void OnActionExecuting(ActionExecutingContext context) { }

        public void OnActionExecuted(ActionExecutedContext context)
        {
            context.HttpContext.Response.Headers.Remove("Server");
        }
    }
}

方法2:使用StartupFilter

如果过滤器不生效,用StartupFilter注入中间件:

using Microsoft.AspNetCore.Builder;
using Microsoft.AspNetCore.Hosting;
using Microsoft.Azure.Functions.Extensions.DependencyInjection;
using Microsoft.Extensions.DependencyInjection;

[assembly: FunctionsStartup(typeof(YourNamespace.Startup))]
namespace YourNamespace
{
    public class Startup : FunctionsStartup
    {
        public override void Configure(IFunctionsHostBuilder builder)
        {
            builder.Services.AddTransient<IStartupFilter, RemoveServerHeaderStartupFilter>();
        }
    }

    public class RemoveServerHeaderStartupFilter : IStartupFilter
    {
        public Action<IApplicationBuilder> Configure(Action<IApplicationBuilder> next)
        {
            return app =>
            {
                app.Use(async (context, nextMiddleware) =>
                {
                    await nextMiddleware();
                    context.Response.Headers.Remove("Server");
                });
                next(app);
            };
        }
    }
}

三、关于host.json配置的补充

你之前在customHeaders中设置"Server": ""的方式,只会将Server头设为空字符串,而非完全移除。如果需要彻底移除,优先用上述中间件/过滤器的方式。

关键注意点

  • 消耗计划下:Azure Functions的前端网关可能会添加额外的响应头,如果最终仍能看到Server: Microsoft-IIS/10.0这类头部,这是Azure平台层添加的,无法通过函数代码移除(需通过Azure Front Door等额外网关层处理)。
  • 专用/弹性计划下:确保你的Kestrel配置正确生效,同时配合中间件移除可能残留的Server头。

内容的提问来源于stack exchange,提问作者ASHWANI MAURYA

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 17:37:41