Yam yuav ua tiav: Lub website HTML response yuav muaj ib qho allowlist tsawg kawg nkaus thiab yuav raug kuaj hauv hom ceeb toom ua ntej hloov mus rau hom thaiv. Txoj kev no haum rau tus pib tshiab uas muaj cai hloov web server, reverse proxy lossis CDN; koj kuj yuav tsum muaj HTTPS, cai nkag mus rau qhov kev teeb tsa thiab ib daim ntawv teev sơ bộ ntawm API, CDN, worker thiab cov kev pabcuam thib peb. Chrome 152 tau sau tseg Connection-Allowlist hauv stable channel txij li 25 Lub Yim Hli 2026 thiab siv rau cov kev txuas uas document lossis worker pib (raws li developer.chrome.com). Qhov feature no tsis hloov chaw rau HTTPS, CSP, authentication lossis kev tiv thaiv server-side code.
Connection-Allowlist tswj dab tsi?
Connection-Allowlist yog HTTP response header uas muaj daim ntawv teev cov endpoint uas ib context raug tso cai txuas lus nrog. Browser yuav thaiv endpoint uas tsis phim policy ua ntej kev txuas raug tsim. Lub hom phiaj yog kom txo cov kev sib txuas uas tsis tau npaj tseg, xws li thaum ib qho code raug txhaj thiab sim xa ntaub ntawv mus rau ib lub server txawv.
Policy raug khi rau txhua context. Document header tswj cov kev txuas uas document tsim; worker header tswj lub worker context uas phim. Header no tsis txwv tus neeg siv kom tsis txhob navigate nws tus kheej, tsis kho malware hauv server thiab tsis daws cov side channel xws li kev kwv yees los ntawm CPU lossis memory (raws li wicg.github.io).
Connection-Allowlist txawv ntawm CSP li cas?
- CSP: faib ntau hom resource los ntawm cov directive xws li
script-srcscript-srcstyle-srcstyle-srcimg-srcimg-srcconnect-srcthiab - connect-src ; CSP tseem tsim nyog rau kev tswj cov ntsiab lus thiab txo qhov kev pheej hmoo XSS.
- Connection-Allowlist: tsom rau pawg endpoint uas document lossis worker raug tso cai txuas, tsis yog tsuas faib raws hom resource xwb.
Siv ua ke:
ob lub mechanism no txhawb nqa ib leeg. Tsis txhob tshem CSP, CORS, CSRF protection, authentication lossis permission vim tsuas yog twb ntxiv allowlist lawm.
- Connection-Allowlist tsis yog yam hloov firewall: firewall tswj traffic ntawm server infrastructure, hos header no tsim ib qho kev txwv hauv browser ntawm tus neeg siv. Kuaj cov cai nkag mus thiab infrastructure ua ntej hloov
- Nrhiav kom paub txheej uas xa HTML: sau tseg tias website, reverse proxy, CDN lossis web server twg yog tus tsim response kawg. Koj yuav tsum muaj cai hloov txheej ntawd, tsis yog tsuas muaj cai kho application source code xwb.
admin@example.comNpaj SSH session lossis server control panel:example.comyog siv SSH, khiav cov lus txib tswj hwm hauv server terminal; hloov - thiab nrog koj cov ntaub ntawv tiag. Tsis txhob paste cov lus txib uas muaj cai tswj hwm yog tseem tsis tau kuaj path.
- Kuaj DNS thiab HTTPS: domain yuav tsum taw rau txheej uas muab website tiag, certificate yuav tsum siv tau, thiab firewall yuav tsum tso cai rau HTTPS port. Connection-Allowlist tsis kho DNS, certificate lossis routing teeb meem.
Ua backup ua ntej hloov:
khaws ib daim qauv ntawm Nginx, Apache lossis CDN configuration nrog allowlist uas siv tam sim no. Sau tseg configuration version thiab txoj kev reload kom thiaj rov qab tau yog website muaj teeb meem.
| Tsim ib qho allowlist tsawg kawg nkaus | Tsis txhob pib nrog wildcard uas dav dhau. Siv DevTools, application log thiab integration documentation los tsim daim ntawv no: | Pawg kev txuas |
|---|---|---|
| Piv txwv | https://example.com | Txoj kev txiav txim response-originTib origin |
| Feem ntau sawv cevด้วย token | https://api.example.com | . |
| API cais | https://cdn.example.com | Ntxiv tsuas yog thaum document lossis worker yeej hu rau API no. |
| CDN | Sib piv cov resource thiab hostname tiag hauv response. | Kev pabcuam thib peb |
Sau thiab cov endpoint uas Web Worker, Service Worker, WebSocket, WebRTC lossis DNS prefetch hu siv yog tias daim ntawv thov siv cov no. Tsis txhob muab txhua hostname uas pom hauv log tso rau hauv allowlist cia li; cov endpoint txawv ntawd tej zaum yog los ntawm lub tsev qiv ntawv uas tsis tsim nyog lossis code uas raug txhaj nkag.
Sau header kom raug raws syntax
Tus nqi ntawm header yog ib qho Structured Field uas muaj ib inner list. Lub token response-origin sawv cev rau origin uas xa document ntawd rov los; cov URL pattern uas seem yog cov hlua URL uas sau tiav. Qhov specification kuj piav txog cov parameter xws li redirects, webrtc thiab report-to.
Connection-Allowlist: (response-origin "https://api.example.com" "https://cdn.example.com")
Qhov piv txwv no tso cai rau document txuas mus rau origin uas muab document, API thiab CDN uas tau teev tseg. Cov URL hauv qhov piv txwv tsuas yog placeholder xwb: hloov example.com nrog hostname tiag, thiab khaws kom raug tib qho protocol, chaw nres nkoj thiab URL pattern uas daim ntawv thov siv. Tsis txhob sau raws hom CSP uas faib cov npeด้วย comma.
Sim siv Report-Only ua ntej thiaj li thaiv
Report-Only pab soj ntsuam cov kev ua txhaum cai yam tsis tau thaiv qhov kev txuas. Qhov no nyab xeeb dua thaum daim ntawv thov muaj SDK, kev tshaj tawm, kev nkag mus rau account hla domain, lossis worker uas tseem tsis tau sau npe tag.
Connection-Allowlist-Report-Only: (response-origin "https://api.example.com" "https://cdn.example.com")
Yog xav sau cov report, teeb tsa reporting endpoint uas koj tswj tau:
Reporting-Endpoints: connection-errors="https://reports.example.com/connection"
Connection-Allowlist-Report-Only: (response-origin "https://api.example.com" "https://cdn.example.com"); report-to=connection-errors
Hloov URL ntawm reporting endpoint mus rau qhov tseeb, thiab tiv thaiv endpoint ntawd ib yam li API uas txais cov ntaub ntawv los ntawm browser. Cov report tej zaum yuav muaj context URL, qhov kev txuas uas ua txhaum cai, allowlist thiab enforce lossis report; txwv tsis pub sau cov ntaub ntawv rhiab heev rau hauv log.
Teeb tsa hauv Nginx lossis Apache

Nginx
Ua hauv ntu server lossis location uas xa HTML rov qab. Cov qauv configuration hauv qab no tsuas yog qauv xwb; khaws koj cov lus qhia root, proxy thiab SSL uas twb muaj lawm:
server {
listen 443 ssl;
server_name example.com;
add_header Connection-Allowlist-Report-Only '(response-origin "https://api.example.com" "https://cdn.example.com")' always;
# Giữ các chỉ thị root, proxy_pass và SSL hiện có ở đây.
}
Hloov peb lub hostname qauv tag nrho mus rau cov nqi tiag. Hauv SSH terminal ntawm server, xyuas syntax ua ntej reload:
sudo nginx -t
sudo systemctl reload nginx
Qhov txiaj ntsig uas yuav tsum tau pom ntawm thawj lo lus txib yog syntax is ok thiab test is successful. Yog qhov kev tshuaj xyuas ua tsis tiav, tsis txhob reload; kho cov ntaub ntawv configuration kom raug mam khiav sudo nginx -tdua. always pab kom header tshwm hauv ntau hom response uas muaj error, tab sis CDN lossis cache nyob rau sab pem hauv ntej tseem yuav tshem lossis sau dua header ntawd tau.
Apache HTTP Server
Hauv VirtualHost uas siv HTTPS lossis directory configuration uas tsim nyog, yuav tsum qhib module headers ua ntej teeb header:
Header always set Connection-Allowlist-Report-Only "(response-origin \"https://api.example.com\" \"https://cdn.example.com\")"
Ua hauv SSH terminal ntawm server:
sudo a2enmod headers
sudo apachectl configtest
sudo systemctl reload apache2
Qhov txiaj ntsig uas yuav tsum tau txais yog Syntax OK. Rau operating system lossis distribution uas siv lwm lub npe service, hloov apache2 nrog Apache service lub npe tiag. Yog configtest muaj error, tsis txhob reload kom txog thaum kho tiav.
Xyuas response thiab cov kev khiav haujlwm tiag
- Xyuas response kawg: khiav hauv client lossis server lub terminal, thiab hloov URL mus rau nplooj ntawv tiag:
curl -sSI https://example.com/ | grep -iE 'connection-allowlist|reporting-endpoints'
Yuav tsum pom header kom raug tom qab CDN, proxy thiab redirect kawg. Yog tsis pom, xyuas qhov chaw uas teeb header, cache thiab cov cai uas sau dua response.
- Xyuas Network: qhib Chrome DevTools, xaiv Network, qhib kev sau log yog xav tau, reload nplooj ntawv thiab soj ntsuam cov request mus rau API, CDN, worker script thiab third-party service.
- Nyeem cov report: faib cov endpoint ua cov uas tsim nyog, cov uas tsis tsim nyog thiab cov uas tsim kev tsis ntseeg. Nrhiav lub tsev qiv ntawv lossis code uas tsim qhov kev txuas ua ntej ntxiv rau allowlist.
- Xyuas worker: lees paub tias URL uas rub worker los yog URL uas xav tau, thiab cov lus txib
fetch()hauv worker tsuas hu cov endpoint uas twb tau tso cai lawm. Yog daim ntawv thov siv Service Worker, xyuas nws nyias ib leeg thiab. - Xyuas redirect: sim kev nkag mus rau account, OAuth callback, kev them nyiaj, kev rub ntaub ntawv thiab kev ceeb toom raws sijhawm. Raws li specification tam sim no, redirect raug thaiv los ntawm lub neej ntawd; tsuas qhib parameter
redirectstom qab sau npe txhua theem thiab tshuaj xyuas qhov kev pheej hmoo lawm xwb. - Xyuas WebRTC: yog muaj kev hu suab lossis video, xyuas STUN/TURN nyias ib leeg. WebRTC muaj lwm hom endpoint mechanism dua li HTTP request, thiab policy tam sim no yuav thaiv tau nws los ntawm lub neej ntawd.
Pom header dhau curl tsuas lees paub tias response muaj header xwb; nws tsis qhia tias tag nrho daim ntawv thov ua haujlwm raug. Tsuas suav tias theem npaj tiav thaum cov kev khiav haujlwm tseem ceeb thiab server log qhia tau qhov txiaj ntsig uas tsim nyog.
Hloov mus rau enforce mode
Tom qab daws cov report uas raug cai lawm, hloov Report-Only header mus ua header uas siv los thaiv tiag:
Connection-Allowlist: (response-origin "https://api.example.com" "https://cdn.example.com")
Yog ua tau, siv rau ib pab nplooj ntawv lossis ib version ntawm daim ntawv thov zuj zus. Tom qab reload web server, rov xyuas dua siv curl, DevTools, kev nkag mus rau account, kev them nyiaj, kev rub ntaub ntawv thiab worker cov haujlwm hauv qab. Yog muaj ntau policy, qhov kev txuas yuav tsum dhau txhua policy uas phim; ib policy uas nruj dua tseem yuav thaiv request tau txawm tias CSP tso cai.
Cov kev ua yuam kev uas nquag ntsib thiab txoj kev daws
Nplooj ntawv tseem txuas tau rau endpoint uas tsis nyob hauv daim ntawv tso cai
Xyuas seb yam koj tab tom pom puas yog Connection-Allowlist los yog tsuas yog pom Connection-Allowlist-Report-Only. Tom qab ntawd xyuas response kawg tom qab redirect, cache, CDN thiab Chrome version uas tab tom siv.
API uas siv tau raug thaiv
Muab URL tiag piv rau pattern, suav nrog protocol, hostname, port thiab path. Kuj xyuas cov request uas tawm los ntawm worker, iframe thiab Service Worker, vim txhua context yuav muaj policy cais.
Kev nkag mus lossis kev them nyiaj ua tsis tau
Xyuas OAuth redirect lossis payment callback ua ntej yuav qhib wildcard. Sau npe txhua theem uas ntseeg tau, tshuaj xyuas cov ntaub ntawv uas dhau ntawm txhua theem, mam li kho parameter redirects lossis callback architecture.
WebRTC tsis ua haujlwm
Xyuas STUN/TURN thiab parameter webrtc. Tsis txhob ntxiv wildcard thoob plaws system tsuas yog kom kho tau sai; yog tseem tsis tau txheeb xyuas endpoint uas tsim nyog, rov qab mus rau Report-Only thaum tab tom tshawb xyuas.
Header muaj syntax yuam kev lossis ploj lawm
Inner list yuav tsum muaj kab nkhaus, URL pattern yog ib txoj hlua nyob hauv cov cim hais lus, hos response-origin yog token uas tsis muab tso rau hauv cov cim hais lus. Khiav nginx -t lossis apachectl configtest, tom qab ntawd xyuas response hla CDN, tsis yog xyuas cov ntaub ntawv configuration qub xwb.
Rollback thiab cov kev txwv ntawm kev ruaj ntseg
Yog ib qho tseem ceeb ua tsis tau haujlwm, thawj zaug rov qab siv configuration uas tau backupไว้. Txoj kev rollback tsawg kawg yog hloov Connection-Allowlist rov mus rau Connection-Allowlist-Report-Only, xyuas syntax, reload web server thiab rov txheeb xyuas response. Yog qhov teeb meem hnyav, tshem enforce header tawm ntawm txheej uas xa HTML; tsis txhob rho HTTPS, CSP, authentication lossis lwm cov txheej txheem tiv thaiv tawm.
- Header no tiv thaiv cov kev txuas uas context pib, tab sis nws tsis thaiv XSS, malware hauv server lossis kev hloov response header yam tsis tau tso cai.
- Allowlist tsis hloov tau authentication, authorization, CORS, CSRF protection, CSP, input validation lossis firewall.
- Wildcard dav heev yuav txo policy tus nqi. Xaiv origin thiab hostname uas qhia meej ua ntej; tsuas qhib port lossis pattern dav thaum muaj laj thawj tau sau tseg lawm.
- Connection Allowlists tam sim no tseem yog ib qho specification ntawm Web Platform Incubator Community Group, tseem tsis yog W3C standard. Xyuas tus cwj pwm ntawm cov browser thiab version uas cov neeg siv tiag tiag siv ua ntej yuav suav tias qhov no yog tib txheej kev tiv thaiv nkaus xwb (raws li github.com).
Daim checklist rau kev siv
- Txheeb xyuas txheej uas xa HTML, cov cai nkag mus, DNS, HTTPS, firewall thiab txoj kev rov qab configuration.
- Sau npe cov endpoint ntawm document, iframe, Web Worker thiab Service Worker.
- Ntxiv
Connection-Allowlist-Report-Onlynrog daim ntawv teev npe uas tsawg kawg nkaus. - Khiav configuration check, reload kom nyab xeeb, txheeb xyuas response tom qab CDN thiab nyeem cov report.
- Xyuas API, redirect, kev nkag mus, kev them nyiaj, kev rub ntaub ntawv, WebRTC thiab cov haujlwm khiav tom qab.
- Hloov mus rau
Connection-Allowlist, saib xyuas cov kev ua yuam kev thiab khaws configuration daim qauv cia rau rollback.
Lub hauv paus ntsiab lus yog: tso cai rau endpoint kom tsawg tshaj plaws, soj ntsuam nrog Report-Only ua ntej, ces tsuas qhib enforce tom qab tau kuaj worker thiab txhua txoj kev redirect lawm.

