HTTP头部参考

请求头(Request Headers)

头部字段用途示例值
Accept客户端接受的内容类型text/html, application/json
Authorization认证凭据Bearer {token}
Content-Type请求体格式application/json; charset=utf-8
User-Agent客户端软件信息Mozilla/5.0 ...
Cookie会话Cookiesession=abc123
Referer来源页面URLhttps://example.com/page
Cache-Control缓存指令no-cache, max-age=3600
Accept-Language首选语言zh-CN,zh;q=0.9,en;q=0.8

响应头(Response Headers)

头部字段用途示例值
Content-Type响应体格式application/json
Set-Cookie设置浏览器Cookieid=a3; HttpOnly; Secure
Location重定向URL(3xx)https://example.com/new
Cache-Control缓存策略public, max-age=86400
ETag资源版本标签"33a64df5"
X-Frame-Options防点击劫持DENY 或 SAMEORIGIN
Access-Control-Allow-Origin跨域访问控制(CORS)* 或 https://allowed.com
Strict-Transport-Security强制HTTPS(HSTS)max-age=31536000; includeSubDomains
Content-Security-Policy允许的资源来源default-src 'self'