เครือข่าย/HTTP
HTTP Headers Parser
แยกวิเคราะห์ส่วนหัว HTTP ดิบ (จาก curl -I, DevTools, raw response) เป็นรายการฟิลด์พร้อมคำอธิบาย และตรวจสอบส่วนหัวความปลอดภัย
Raw HTTP headers from curl -I or the Network tab in DevTools look like one solid block of text. This tool breaks it down into individual fields, explains what each header does, and flags common missing security headers.
How to use it
- Paste raw headers (curl -I output, the Headers tab in DevTools, or a copied raw response).
- Each header is parsed out individually with a short explanation of what it means.
- Missing security headers (Content-Security-Policy, X-Content-Type-Options, etc.) are flagged with a warning.
Common uses
- Quickly checking a site's security headers before a release or an audit.
- Understanding an unfamiliar header from a third-party API response without looking it up every time.
- Debugging caching or CORS issues by analyzing the server's response headers.
Things to keep in mind
Header order mostly doesn't matter for HTTP, except in rare cases involving repeated headers of the same type (e.g. multiple Set-Cookie headers).
A missing security header isn't always a mistake — some of them (HSTS, for example) only make sense for HTTPS sites or specific use cases.
บทความเกี่ยวกับเครื่องมือนี้: HTTP Headers: เมทาดาต้าที่มาพร้อมกับทุกคำขอและการตอบกลับ
คำถามที่พบบ่อย
เฮดเดอร์คำขอกับเฮดเดอร์ตอบกลับต่างกันอย่างไร?
เฮดเดอร์คำขอถูกส่งโดยไคลเอนต์เพื่ออธิบายสิ่งที่ร้องขอ (เช่น Accept หรือ Authorization) ส่วนเฮดเดอร์ตอบกลับถูกส่งโดยเซิร์ฟเวอร์เพื่ออธิบายสิ่งที่ส่งคืน (เช่น Content-Type หรือ Cache-Control)
ทำไมชื่อเฮดเดอร์บางตัวถึงแสดงด้วยตัวพิมพ์ใหญ่เล็กต่างกัน?
ชื่อเฮดเดอร์ HTTP ไม่สนใจตัวพิมพ์ใหญ่เล็กตามข้อกำหนด ดังนั้น Content-Type และ content-type จึงเทียบเท่ากัน — เซิร์ฟเวอร์และเครื่องมือต่าง ๆ เพียงแค่มีธรรมเนียมการแสดงผลต่างกัน
การแยกวิเคราะห์เฮดเดอร์ที่นี่ส่งไปที่ไหนหรือไม่?
ไม่ การแยกวิเคราะห์ทั้งหมดทำงานในเบราว์เซอร์ของคุณ ไม่มีการอัปโหลดไปยังเซิร์ฟเวอร์
ทำไมเฮดเดอร์ Set-Cookie หลายตัวถึงปรากฏในการตอบกลับเดียวกันได้?
HTTP อนุญาตให้เฮดเดอร์เดียวกันซ้ำได้เมื่อสมเหตุสมผล — Set-Cookie เป็นตัวอย่างที่พบบ่อยที่สุด เพราะคุกกี้แต่ละตัวที่ตั้งค่าต้องการบรรทัดและแอตทริบิวต์ของตัวเอง
ลำดับของเฮดเดอร์มีความสำคัญหรือไม่?
แทบไม่สำคัญเลย ยกเว้นเมื่อเฮดเดอร์เดียวกันปรากฏหลายครั้ง — ในกรณีนั้นลำดับระหว่างอินสแตนซ์ที่ซ้ำกันอาจมีความสำคัญ (เช่นสำหรับเฮดเดอร์ Set-Cookie หลายตัว)