HTTP Response Headers
HTTP response headers are a series of header fields sent by the server when responding to a client's HTTP request. They provide additional information about the response and server instructions.
The following are some common HTTP response headers:
| Response Header (English) | Response Header (Chinese) | Description |
|---|---|---|
| Date | Date | The date and time the response was generated. Example: Wed, 18 Apr 2024 12:00:00 GMT |
| Server | Server | The name and version of the server software. Example: Apache/2.4.1 (Unix) |
| Content-Type | Content-Type | The media type (MIME type) of the response body, such astext/html; charset=UTF-8, application/jsonetc. |
| Content-Length | Content-Length | The size of the response body in bytes. Example: 3145 |
| Content-Encoding | Content-Encoding | The compression encoding of the response body, such asgzip, deflateetc. |
| Content-Language | Content-Language | The language of the response body. Example: zh-CN |
| Content-Location | Content-Location | The URI of the response body. Example: /index.html |
| Content-Range | Content-Range | The byte range of the response body, used for chunked transfer. Example: bytes 0-999/8000 |
| Cache-Control | Cache-Control | Controls the caching behavior of the response. For example, no-cache means it must be requested again. |
| Connection | Connection | Manages connection options, such askeep-aliveorclose, keep-alive means the connection will not be closed after transfer.. |
| Set-Cookie | Set-Cookie | Sets the client's cookie. Example: sessionId=abc123; Path=/; Secure |
| Expires | Expires | The expiration date and time of the response body. Example: Thu, 18 Apr 2024 12:00:00 GMT |
| Last-Modified | Last-Modified | The date and time when the resource was last modified. Example: Wed, 18 Apr 2024 11:00:00 GMT |
| ETag | Entity Tag | An identifier for a specific version of a resource. Example: "33a64df551425fcc55e6" |
| Location | Location | The URI used for redirection. Example: /newresource |
| Pragma | Implementation-Specific Directives | Contains implementation-specific directives, such asno-cache。 |
| WWW-Authenticate | Authentication Information | Authentication information, typically used for HTTP authentication. Example: Basic realm="Access to the site" |
| Accept-Ranges | Accept-Ranges | Specifies the acceptable request range types. Example: bytes |
| Age | Elapsed Time | The number of seconds elapsed after the response was generated, from the origin server to the proxy server. Example: 24 |
| Allow | Allow | Lists the HTTP methods allowed for the resource. Example: GET, POST, HEAD, etc. |
| Vary | Vary | Tells downstream proxies how to use response headers to determine whether a response can be fetched from the cache. Example: Accept |
| Strict-Transport-Security | Strict-Transport-Security | Instructs the browser to communicate with the server only over HTTPS. Example: max-age=31536000; includeSubDomains |
| X-Frame-Options | Frame Options | Controls whether the page is allowed to be displayed in a frame, preventing clickjacking attacks. Example: SAMEORIGIN |
| X-Content-Type-Options | Content Type Options | Instructs the browser not to attempt to guess the MIME type of a resource. Example: nosniff |
| X-XSS-Protection | XSS Protection | Controls the browser's XSS filtering and blocking. Example: 1; mode=block |
| Public-Key-Pins | Public Key Pinning | HTTP header for HTTP Public Key Pinning (HPKP), a security mechanism used to prevent man-in-the-middle attacks. Example: pin-sha256="base64+primarykey"; pin-sha256="base64+backupkey"; max-age=expireTime |
These response headers may vary in actual HTTP responses; the specific values depend on the server's configuration and processing logic.
Other Extensions