You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Service部署的.NET 6应用HSTS Header配置问题求助

问题:Azure App Service上的.NET 6 Web应用HSTS Header不符合预期

我使用.NET 6开发了一个Web应用并部署在Azure App Service上,发现Strict-Transport-Security Header仅包含值max-age=31536000,而非预期的max-age=31536000;includeSubDomains;preload。

HSTS Header显示情况

已尝试的无效方法

  • 方法1:URL重写规则
<rewrite>
    <rules>
        <rule name="HTTP to HTTPS redirect" stopProcessing="true">
            <match url="(.*)" />
            <conditions>
                <add input="{HTTPS}" pattern="off" ignoreCase="true" />
            </conditions>
            <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" />
        </rule>
    </rules>
    <outboundRules>
        <rule name="Add Strict-Transport-Security when HTTPS" enabled="true">
            <match serverVariable="RESPONSE_Strict_Transport_Security" pattern=".*" />
            <conditions>
                <add input="{HTTPS}" pattern="on" ignoreCase="true" />
            </conditions>
            <action type="Rewrite" value="max-age=31536000;includeSubDomains;preload" />
        </rule>
    </outboundRules>
</rewrite>
  • 方法2:添加自定义Header
<add name="Strict-Transport-Security" value="max-age=31536000; includeSubDomains; preload" />
  • 方法3:Program.cs中配置HSTS
builder.Services.AddHsts(options =>
{
    options.Preload = true;
    options.IncludeSubDomains = true;
    options.MaxAge = TimeSpan.FromDays(365);
});

app.UseHsts();

内容的提问来源于stack exchange,提问作者Shah Rizar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 17:32:48