Secure
Secure sets a practical default set of security headers.
app.Use(middleware.Secure())
Defaults include:
X-XSS-Protection: 0X-Content-Type-Options: nosniffX-Frame-Options: SAMEORIGINReferrer-Policy: no-referrerCross-Origin-Resource-Policy: same-origin
Use SecureWithConfig to add CSP or HSTS.
app.Use(middleware.SecureWithConfig(middleware.SecureConfig{
ContentSecurityPolicy: "default-src 'self'",
HSTSMaxAge: 31536000,
}))
HSTS is only written for secure requests.