Adding custom headers to Traefik is giving strange behaviour

Viewed 786

Inside my docker-compose.yml I define my Traefik route like so:

labels:
  - 'traefik.enable=true'
  - 'traefik.docker.network=traefik'
  - 'traefik.http.routers.nginx.entrypoints=http'
  - 'traefik.http.routers.nginx.rule=Host(`${DOMAIN}`) || Host(`www.${DOMAIN}`)'
  - 'traefik.http.routers.nginx.middlewares=redirect@file'
  - 'traefik.http.routers.nginx-https.rule=Host(`${DOMAIN}`) || Host(`www.${DOMAIN}`)'
  - 'traefik.http.routers.nginx-https.tls=true'
  - 'traefik.http.routers.nginx-https.tls.certresolver=${DNS_PROVIDER}'
  - 'traefik.http.routers.nginx-https.tls.domains[0].main=${DOMAIN}'
  - 'traefik.http.routers.nginx-https.tls.domains[1].main=www.${DOMAIN}'
  - 'traefik.http.routers.nginx.service=nginx'
  - 'traefik.http.services.nginx.loadbalancer.server.port=80'
  - 'traefik.http.services.nginx.loadBalancer.passHostHeader=true'
  - 'traefik.http.middlewares.https_redirect.redirectscheme.scheme=https'
  - 'traefik.http.middlewares.https-redirect.redirectscheme.scheme=https'
  - 'traefik.http.middlewares.https-redirect.headers.customrequestheaders.X-Forwarded-Proto=https'
  - 'traefik.http.routers.nginx.middlewares=https-redirect'
  - 'traefik.http.middlewares.https_redirect.redirectscheme.permanent=true'
  - 'traefik.http.routers.http_catchall.rule=HostRegexp(`{any:.+}`)'
  - 'traefik.http.routers.http_catchall.entrypoints=http'
  - 'traefik.http.routers.http_catchall.middlewares=https_redirect'
  - 'traefik.http.middlewares.https-redirect.headers.customresponseheaders.Set-Cookie=Path=/; HttpOnly; Secure'
  - 'traefik.http.middlewares.https-redirect.headers.customresponseheaders.X-Powered-By=PHP'
  - 'traefik.http.middlewares.https-redirect.headers.customresponseheaders.HTTPServer=PHP'

I try to set a global traefik.yaml:

tls:
  options:
    default:
      minVersion: VersionTLS12
      sniStrict : true
      cipherSuites:
        - TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
        - TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
        - TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
        - TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
        - TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
        - TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305

    mintls13:
      minVersion: VersionTLS13
http:
  middlewares:
    all-sites:
      redirectScheme:
        scheme: https
        permanent: true
      rateLimit:
        average: 100
        brust: 50
      headers:
        frameDeny: true
        sslRedirect: true
        accessControlAllowMethods:
          - GET
          - POST
        contentTypeNosniff: true
        browserXssFilter: true
        stsPreload: true
        stsIncludeSubdomains: true
        sslForceHost: true
        sslRedirec: true

I see these get loaded by Traefik in the logs:

"customResponseHeaders\":{\"HTTPServer\":\"PHP\",\"Set-Cookie\":\"Path=/; HttpOnly; Secure\",\"X-Powered-By\":\"PHP\"}},\

But, when I run a whatweb I see:

[200 OK] Cookies[...._session,Path,XSRF-TOKEN], Country[UNITED STATES][US], HTML5, HTTPServer[nginx], HttpOnly[...._session,Path], IP[x.xx.xxx.xx], PHP[7.4.21], PasswordField[password], Strict-Transport-Security[max-age=63072000], Title[......], UncommonHeaders[x-content-type-options], X-Frame-Options[SAMEORIGIN], X-Powered-By[PHP/7.4.21], X-XSS-Protection[1; mode=block], nginx

Inside my nginx I have:

add_header X-Frame-Options "SAMEORIGIN";
add_header X-XSS-Protection "1; mode=block";
add_header X-Content-Type-Options "nosniff";
add_header X-Real-IP "$remote_user";
add_header 'Access-Control-Allow-Origin' $allow_origin;

client_max_body_size 10M;

# RFC 6797
add_header Strict-Transport-Security "max-age=63072000" always;

set_real_ip_from  172.18.0.0/24;
real_ip_header    X-Forwarded-For;

# Disallow
add_header Set-Cookie "Path=/; HttpOnly; Secure";

# Remove info disclosure
server_tokens off;

# SWEET32 - TLSv1.2 defualt enabled
ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;

But only certain headers are taking effect on certain files and I really can't work out what I'm doing wrong to just try and remove the server tokens and add my custom security headers. Any help appreciated.

0 Answers
Related