<system.webServer> <httpErrors errorMode="Detailed" /> <httpProtocol> <customHeaders> <add name="X-Content-Type-Options" value="nosniff" /> <add name="X-XSS-Protection" value="1" /> <add name="Strict-Transport-Security" value="max-age=31536000" /> <add name="X-Download-Options" value="noopen" /> <add name="X-Permitted-Cross-Domain-Policies" value="master-only" /> <add name="Referrer-Policy" value="origin-when-cross-origin" /> </customHeaders> </httpProtocol> </system.webServer>
设置完后IIS HTTP响应头设置界面显示如下



