← Back to Apache Course | Chapter 4: Security | Lesson 4 of 4

Security Headers जोड़ना

Security headers वे extra instructions हैं जो Apache हर response में add करता है, browser को protections enforce करने के लिए कहते हुए -- जैसे page को frame में load करने से मना करना, या हमेशा HTTPS इस्तेमाल करना -- जो browser अपने आप, default से apply नहीं करता।

सिर्फ Code नहीं, Headers क्यों

कुछ protections browser से ही enforce होना सबसे अच्छा है, और headers server का यह तरीका है browser को उन्हें on करने के लिए कहने का। उन्हें Apache में centrally set करना (हर individual page के application code में नहीं) guarantee करता है कि वे site के हर response पर apply हों, static files और error pages समेत जिन्हें application कभी छूता ही नहीं।

ज़रूरी Headers

Strict-Transport-Security (HSTS) browser को एक set period के लिए हमेशा सिर्फ HTTPS पर connect करने को कहता है, भले ही कोई link http:// की ओर point करे। X-Content-Type-Options: nosniff browser को किसी file के type को server द्वारा declare किए गए से अलग guess करने से रोकता है। X-Frame-Options: SAMEORIGIN (या नया Content-Security-Policy: frame-ancestors) page को किसी दूसरी site के <iframe> में embed होने से रोकता है, एक common clickjacking defense।

Content-Security-Policy

Content-Security-Policy (CSP) इन headers में सबसे powerful और सबसे complex है -- यह आपको exactly declare करने देता है कि scripts, styles, images, और दूसरे resources किन sources से load हो सकते हैं, जो cross-site scripting (XSS) vulnerability से हो सकने वाले damage को meaningfully limit करता है। इसे सही तरीके से configure करने में असली effort भी लगती है, क्योंकि एक ज़्यादा strict policy site के legitimate हिस्सों को तोड़ सकती है।

इन्हें mod_headers से Set करना

ये सब same तरीके से set होते हैं, Header always set (mod_headers lesson से) इस्तेमाल करते हुए ताकि वे error responses पर भी apply हों, आमतौर पर main VirtualHost या एक global config file में ताकि server की हर site को वे consistently मिलें।

Note: deploy करने के बाद securityheaders.com जैसे किसी tool या live site पर curl -I से अपने headers test करें -- किसी directive में typo होना आसान है जिसका चुपचाप मतलब है header actually कभी भेजा ही नहीं जाता।

उदाहरण: A common security header baseline

apacheconf
<IfModule mod_headers.c>
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
    Header always set X-Content-Type-Options "nosniff"
    Header always set X-Frame-Options "SAMEORIGIN"
    Header always set Content-Security-Policy "default-src 'self'"
</IfModule>
{# Flagged by hand after confirming a runner can't handle this example (a shell command / go.mod file stored as a TopicExample, a language feature the configured runner version doesn't support, or output that blows a runner's sandbox limit) -- see TopicExample.norun. Never render the run button for these, regardless of language, since it would just fail at execute_code (or worse, hang the Judge0 queue on a submission that can never finish cleanly). #}

⚠️ This example can't run in the browser editor. Try it in your own local environment instead.

{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. security headers को Header always set की जगह Header set से set करना, ताकि वे ठीक उन error responses पर missing हों जहाँ कोई attacker सबसे ज़्यादा probe कर रहा हो।
  2. test किए बिना एक बहुत strict Content-Security-Policy लिखना, site को actually चाहिए होने वाले legitimate scripts/styles/fonts तोड़ते हुए।
  3. यह confirm करने से पहले कि HTTPS हर जगह पूरी तरह काम कर रहा है, बहुत लंबे max-age के साथ HSTS add करना -- कुछ टूटने पर भी browsers उस duration के लिए HTTP पर fall back करने से मना कर देंगे।
चैप्टर सारांश
  • Basic Auth, IP-based access rules, और SSL/TLS हर एक access control की एक layer जोड़ते हैं -- simple password prompts से, network location से restrict करने तक, एक असली, auto-renewing certificate से connection को खुद encrypt करने तक।
  • Security headers (HSTS, X-Content-Type-Options, X-Frame-Options, Content-Security-Policy), Header always set से centrally set किए गए, browser को हर response पर protections enforce करने के लिए कहते हैं, error pages समेत।
🔒

Chapter Quiz — Complete all 4 topics to unlock

0/4 topics done

Complete these topics first:

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.