Azure API Management策略:如何动态删除未被允许的响应头
Azure API Management 响应头白名单清理方案
你可以通过策略表达式+递归调用实现响应头的白名单过滤,无需硬编码所有要删除的头,只需定义允许保留的头列表,自动清理其余所有头。
单个操作级别的实现
在目标API操作的<outbound>策略中添加以下代码,按需修改白名单数组:
<outbound> <!-- 定义当前操作允许保留的响应头白名单 --> <set-variable name="allowedHeaders" value="[new string[] { 'Content-Type', 'Content-Length', 'X-Custom-Allowed-Header' }]" /> <!-- 遍历并删除非白名单响应头 --> <choose> <when condition="@(context.Response.Headers != null)"> <set-header name="@(context.Response.Headers.Keys.First())" exists-action="delete"> <when condition="@(!((string[])context.Variables["allowedHeaders"]).Contains(context.Response.Headers.Keys.First(), StringComparer.OrdinalIgnoreCase))" /> </set-header> <!-- 递归执行,直到所有非白名单头被清理 --> <choose> <when condition="@(context.Response.Headers.Any(h => !((string[])context.Variables["allowedHeaders"]).Contains(h.Key, StringComparer.OrdinalIgnoreCase)))"> <outbound> <set-header name="@(context.Response.Headers.Keys.First(h => !((string[])context.Variables["allowedHeaders"]).Contains(h, StringComparer.OrdinalIgnoreCase)))" exists-action="delete" /> </outbound> </when> </choose> </when> </choose> </outbound>
全局API级别的实现
如果所有操作共用同一套白名单,可将代码放在API级别的<outbound>策略中:
<outbound> <!-- 定义全局允许的响应头白名单 --> <set-variable name="globalAllowedHeaders" value="[new string[] { 'Content-Type', 'Content-Length', 'X-Global-Allowed-Header' }]" /> <choose> <when condition="@(context.Response.Headers != null)"> <set-header name="@(context.Response.Headers.Keys.First())" exists-action="delete"> <when condition="@(!((string[])context.Variables["globalAllowedHeaders"]).Contains(context.Response.Headers.Keys.First(), StringComparer.OrdinalIgnoreCase))" /> </set-header> <choose> <when condition="@(context.Response.Headers.Any(h => !((string[])context.Variables["globalAllowedHeaders"]).Contains(h.Key, StringComparer.OrdinalIgnoreCase)))"> <outbound> <set-header name="@(context.Response.Headers.Keys.First(h => !((string[])context.Variables["globalAllowedHeaders"]).Contains(h, StringComparer.OrdinalIgnoreCase)))" exists-action="delete" /> </outbound> </when> </choose> </when> </choose> </outbound>
关键说明
- 大小写不敏感处理:使用
StringComparer.OrdinalIgnoreCase确保头名称匹配不受大小写影响,符合HTTP协议规范。 - 灵活定制:单个操作可单独定义
allowedHeaders变量,覆盖全局配置,实现不同操作的差异化白名单。 - 递归终止逻辑:当所有响应头都在白名单内时,递归自动停止,避免无限循环。
- 验证方式:部署策略后,调用API并查看响应头,确认仅白名单内的头被保留。
内容的提问来源于stack exchange,提问作者Jason
相关产品推荐
相关产品推荐

