You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot应用启用HTTP Strict Transport Security(HSTS)失败排查

问题:Spring Boot配置HSTS头后响应中未出现Strict-Transport-Security

我按照Spring Security 4.0.2的文档配置了HSTS头,但响应里始终没有出现Strict-Transport-Security字段,相关配置和当前响应信息如下:

pom.xml依赖配置

<dependencies>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-web</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-actuator</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-test</artifactId>
        <scope>test</scope>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-thymeleaf</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.security</groupId>
        <artifactId>spring-security-web</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.security</groupId>
        <artifactId>spring-security-config</artifactId>
    </dependency>
</dependencies>

WebSecurityConfig配置类

import org.springframework.context.annotation.Configuration;
import org.springframework.security.config.annotation.web.builders.HttpSecurity;
import org.springframework.security.config.annotation.web.configuration.EnableWebSecurity;
import org.springframework.security.config.annotation.web.configuration.WebSecurityConfigurerAdapter;

@EnableWebSecurity
@Configuration
public class WebSecurityConfig extends WebSecurityConfigurerAdapter {
    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .headers()
                .httpStrictTransportSecurity()
                    .includeSubDomains(true)
                    .maxAgeInSeconds(31536000);
    }
}

当前响应头列表

cache-control → no-cache, no-store, max-age=0, must-revalidate
content-language → en-GB
content-type → text/html;charset=UTF-8
date → Thu, 24 May 2018 14:10:29 GMT
expires → 
pragma → no-cache
transfer-encoding → chunked
x-application-context → application:9000
x-content-type-options → nosniff
x-frame-options → SAMEORIGIN
x-xss-protection → 1; mode=block

解决方案:HSTS仅在HTTPS请求下生效

你遇到的问题核心原因是HSTS头只会在HTTPS协议的请求中返回,HTTP请求下Spring Security不会添加这个头。下面是具体的排查和解决步骤:

1. 确认应用是否运行在HTTPS环境

如果你的应用当前是通过HTTP访问(比如本地开发默认的8080端口),那肯定看不到Strict-Transport-Security头。你需要配置Spring Boot启用HTTPS:

步骤1:生成自签名证书(本地测试用)

用keytool命令生成一个PKCS12格式的证书:

keytool -genkeypair -alias tomcat -keyalg RSA -keysize 2048 -storetype PKCS12 -keystore keystore.p12 -validity 3650

执行后按照提示输入密码和相关信息,生成的keystore.p12文件放到项目的src/main/resources目录下。

步骤2:配置application.properties

添加HTTPS相关配置:

server.port=8443
server.ssl.key-store=classpath:keystore.p12
server.ssl.key-store-password=你设置的密码
server.ssl.keyStoreType=PKCS12
server.ssl.keyAlias=tomcat

2. 验证配置正确性

你的Spring Security配置本身是没问题的,但可以确保没有其他配置覆盖HSTS的设置。比如如果有自定义的Filter修改响应头,需要检查是否会移除HSTS字段。

3. 测试HTTPS请求

启动应用后,用浏览器访问https://localhost:8443,或者用curl命令查看响应头:

curl -v https://localhost:8443 --insecure

此时你应该能看到Strict-Transport-Security头出现在响应中。

额外说明

如果你的应用是部署在反向代理(如Nginx)后面,需要确保反向代理将HTTPS的请求信息传递给Spring Boot,或者直接在反向代理层面配置HSTS头。比如Nginx的配置可以添加:

add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;

内容的提问来源于stack exchange,提问作者kk.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 10:11:31