You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure API Management策略:如何动态删除未被允许的响应头

Azure API Management 响应头白名单清理方案

你可以通过策略表达式+递归调用实现响应头的白名单过滤,无需硬编码所有要删除的头,只需定义允许保留的头列表,自动清理其余所有头。

单个操作级别的实现

在目标API操作的<outbound>策略中添加以下代码,按需修改白名单数组:

<outbound>
    <!-- 定义当前操作允许保留的响应头白名单 -->
    <set-variable name="allowedHeaders" value="[new string[] { 'Content-Type', 'Content-Length', 'X-Custom-Allowed-Header' }]" />
    
    <!-- 遍历并删除非白名单响应头 -->
    <choose>
        <when condition="@(context.Response.Headers != null)">
            <set-header name="@(context.Response.Headers.Keys.First())" exists-action="delete">
                <when condition="@(!((string[])context.Variables["allowedHeaders"]).Contains(context.Response.Headers.Keys.First(), StringComparer.OrdinalIgnoreCase))" />
            </set-header>
            <!-- 递归执行,直到所有非白名单头被清理 -->
            <choose>
                <when condition="@(context.Response.Headers.Any(h => !((string[])context.Variables["allowedHeaders"]).Contains(h.Key, StringComparer.OrdinalIgnoreCase)))">
                    <outbound>
                        <set-header name="@(context.Response.Headers.Keys.First(h => !((string[])context.Variables["allowedHeaders"]).Contains(h, StringComparer.OrdinalIgnoreCase)))" exists-action="delete" />
                    </outbound>
                </when>
            </choose>
        </when>
    </choose>
</outbound>

全局API级别的实现

如果所有操作共用同一套白名单,可将代码放在API级别的<outbound>策略中:

<outbound>
    <!-- 定义全局允许的响应头白名单 -->
    <set-variable name="globalAllowedHeaders" value="[new string[] { 'Content-Type', 'Content-Length', 'X-Global-Allowed-Header' }]" />
    
    <choose>
        <when condition="@(context.Response.Headers != null)">
            <set-header name="@(context.Response.Headers.Keys.First())" exists-action="delete">
                <when condition="@(!((string[])context.Variables["globalAllowedHeaders"]).Contains(context.Response.Headers.Keys.First(), StringComparer.OrdinalIgnoreCase))" />
            </set-header>
            
            <choose>
                <when condition="@(context.Response.Headers.Any(h => !((string[])context.Variables["globalAllowedHeaders"]).Contains(h.Key, StringComparer.OrdinalIgnoreCase)))">
                    <outbound>
                        <set-header name="@(context.Response.Headers.Keys.First(h => !((string[])context.Variables["globalAllowedHeaders"]).Contains(h, StringComparer.OrdinalIgnoreCase)))" exists-action="delete" />
                    </outbound>
                </when>
            </choose>
        </when>
    </choose>
</outbound>

关键说明

  • 大小写不敏感处理:使用StringComparer.OrdinalIgnoreCase确保头名称匹配不受大小写影响,符合HTTP协议规范。
  • 灵活定制:单个操作可单独定义allowedHeaders变量,覆盖全局配置,实现不同操作的差异化白名单。
  • 递归终止逻辑:当所有响应头都在白名单内时,递归自动停止,避免无限循环。
  • 验证方式:部署策略后,调用API并查看响应头,确认仅白名单内的头被保留。

内容的提问来源于stack exchange,提问作者Jason

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 19:41:23