mod_headers का उपयोग
mod_headers आपको Apache config से HTTP response और request headers add, change, या remove करने देता है -- जिसका इस्तेमाल security headers, caching hints, और CORS के लिए लगातार होता है।इसे Enable करना
Ubuntu/Debian पर: sudo a2enmod headers फिर reload। RHEL-family systems पर यह आमतौर पर compiled in होता है और बस LoadModule headers_module modules/mod_headers.so uncomment करने की ज़रूरत होती है।
Header Directive
Header set Name "value" एक response header set करता है, same नाम वाले किसी existing header को overwrite करते हुए। Header add same नाम का एक existing header हटाए बिना एक नया header add करता है। Header unset और Header always unset किसी header को पूरी तरह remove करते हैं -- Server या X-Powered-By जैसी server internals reveal करने वाली information हटाने के लिए useful।
Conditional Headers
Header एक condition ले सकता है, सबसे आम तौर पर Header always set ..., जहाँ always यह पक्का करता है कि header error responses (4xx/5xx) पर भी set हो, न कि सिर्फ successful responses पर -- security headers के लिए important है, जिन्हें सिर्फ happy path पर नहीं, हर response पर apply होना चाहिए।
Security और Caching Use Cases
mod_headers का सबसे common real-world इस्तेमाल security headers add करना है (Security Headers lesson में गहराई से covered) जैसे X-Content-Type-Options और Strict-Transport-Security, plus static asset directories पर caching headers जैसे Cache-Control browsers को बताने के लिए कि किसी file को दोबारा request करने से पहले कितनी देर रखें।
उदाहरण: Setting security and caching headers
<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
Header unset Server
</IfModule>
<FilesMatch "\.(css|js|jpg|png)$">
Header set Cache-Control "max-age=604800, public"
</FilesMatch>
{# Flagged by hand after confirming a runner can't handle this example
(a shell command / go.mod file stored as a TopicExample, a language
feature the configured runner version doesn't support, or output
that blows a runner's sandbox limit) -- see TopicExample.norun.
Never render the run button for these, regardless of language,
since it would just fail at execute_code (or worse, hang the
Judge0 queue on a submission that can never finish cleanly). #}
- एक security header के लिए
alwaysके बिनाHeader setइस्तेमाल करना, ताकि यह ठीक उन error responses (जैसे एक blocked request) पर missing हो जहाँ यह सबसे ज़्यादा मायने रखता है। - यह भूल जाना कि
mod_headersको अलग से enable करना ज़रूरी है -- ऐसेHeaderdirectives लिखना जिन्हें Apache module on होने तक बिल्कुल पहचानता ही नहीं। - application और Apache के config दोनों में conflicting Cache-Control headers set करना, यह unclear छोड़ते हुए कि किसी given response के लिए actually कौन सा जीतता है।
Chapter Quiz — Complete all 5 topics to unlock
0/5 topics done
Complete these topics first: