Ether Framework
Unified API docs for Ether modules
Loading...
Searching...
No Matches
SecurityHeadersPolicy.java
Go to the documentation of this file.
1package dev.rafex.ether.http.security.headers;
2
3/*-
4 * #%L
5 * ether-http-security
6 * %%
7 * Copyright (C) 2025 - 2026 Raúl Eduardo González Argote
8 * %%
9 * Permission is hereby granted, free of charge, to any person obtaining a copy
10 * of this software and associated documentation files (the "Software"), to deal
11 * in the Software without restriction, including without limitation the rights
12 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
13 * copies of the Software, and to permit persons to whom the Software is
14 * furnished to do so, subject to the following conditions:
15 *
16 * The above copyright notice and this permission notice shall be included in
17 * all copies or substantial portions of the Software.
18 *
19 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
20 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
21 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
22 * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
23 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
24 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
25 * THE SOFTWARE.
26 * #L%
27 */
28
29import java.util.LinkedHashMap;
30import java.util.Map;
31
32/**
33 * Política de seguridad para encabezados HTTP.
34 * <p>
35 * Configura encabezados de seguridad como CSP, HSTS, X-Frame-Options,
36 * para proteger contra ataques comunes como XSS, clickjacking, etc.
37 * </p>
38 */
39public record SecurityHeadersPolicy(boolean contentTypeOptions, boolean frameOptions, boolean referrerPolicy,
40 boolean permissionsPolicy, boolean hsts, boolean noStore, String contentSecurityPolicy,
41 Map<String, String> customHeaders) {
42
44 customHeaders = customHeaders == null ? Map.of() : Map.copyOf(customHeaders);
45 }
46
47 public static SecurityHeadersPolicy defaults() {
48 return new SecurityHeadersPolicy(true, true, true, true, true, true,
49 "default-src 'self'; frame-ancestors 'none'; base-uri 'self'", Map.of());
50 }
51
52 public Map<String, String> headers() {
53 final var headers = new LinkedHashMap<String, String>();
54 if (contentTypeOptions) {
55 headers.put("X-Content-Type-Options", "nosniff");
56 }
57 if (frameOptions) {
58 headers.put("X-Frame-Options", "DENY");
59 }
60 if (referrerPolicy) {
61 headers.put("Referrer-Policy", "no-referrer");
62 }
63 if (permissionsPolicy) {
64 headers.put("Permissions-Policy", "geolocation=(), microphone=(), camera=()");
65 }
66 if (hsts) {
67 headers.put("Strict-Transport-Security", "max-age=31536000; includeSubDomains");
68 }
69 if (noStore) {
70 headers.put("Cache-Control", "no-store");
71 }
72 if (contentSecurityPolicy != null && !contentSecurityPolicy.isBlank()) {
73 headers.put("Content-Security-Policy", contentSecurityPolicy);
74 }
75 headers.putAll(customHeaders);
76 return headers;
77 }
78}
Security response headers and default header profiles.
record SecurityHeadersPolicy(boolean contentTypeOptions, boolean frameOptions, boolean referrerPolicy, boolean permissionsPolicy, boolean hsts, boolean noStore, String contentSecurityPolicy, Map< String, String > customHeaders)
Política de seguridad para encabezados HTTP.