用python无法检索CSP头

时间:2018-03-06 10:35:47

标签: python http header response content-security-policy

我想检索某个网站的所有标头,在此示例中为" https://www.facebook.com"如下:

import urllib2
enter code here`req = urllib2.Request('https://www.facebook.com/')
res = urllib2.urlopen(req)
print res.info()
res.close();

导致此回复:

X-XSS-Protection: 0
Pragma: no-cache
Cache-Control: private, no-cache, no-store, must-revalidate
X-Frame-Options: DENY
Strict-Transport-Security: max-age=15552000; preload
X-Content-Type-Options: nosniff
Expires: Sat, 01 Jan 2000 00:00:00 GMT
Set-Cookie: sb=1GyeWkJzGbmX-VUyBi26; expires=Thu, 05-Mar-2020 10:26:28 GMT; Max-Age=63071999; path=/; domain=.facebook.com; secure; httponly
Vary: Accept-Encoding
Content-Type: text/html; charset=UTF-8
X-FB-Debug: X9aSOOKs6/aER1yuY4iUUIZrj4yTKtKSUAZ/AFE37IieCe8O4MSsFc5xlQ0LoQyHnbrSL4DaYiTVUUkFZeDrsqqg==
Date: Tue, 06 Mar 2018 10:26:29 GMT
Connection: close

我可以检索除Content-Security-Policy(csp)之外的所有标头; 但每当我在geekflare csp test上测试时 它成功检索了所有标题,包括csp one。

1 个答案:

答案 0 :(得分:0)

似乎我忘了在请求中设置User-Agent。