debug redirect
ตรวจ status, URL สุดท้าย, DNS target และสัญญาณ social preview
- 1. HTTP
ตาม redirect chain และ response สุดท้าย
- 2. DNS
ยืนยัน apex, www และ CNAME ชี้ไปยังเป้าหมายที่ถูกต้อง
- 3. URL Parse
แยก query parameter และการเปลี่ยน canonical path
ตรวจรหัสสถานะ ลำดับการเปลี่ยนทาง และ header ตอบกลับของ URL สาธารณะเพื่อเช็ค deployment และ SEO
อินพุต / ผลลัพธ์
อินพุต ผลลัพธ์ และการคัดลอกอยู่ในพื้นที่หลักนี้ ตัวอย่างและรายการตรวจอยู่ด้านล่าง
เซสชันในเครื่อง
สถานะอินพุตเก็บไว้เฉพาะในเบราว์เซอร์นี้ เพื่อกู้คืนงานล่าสุดได้โดยไม่ต้องมีบัญชี
เปิดตัวอย่าง รายการตรวจ และเครื่องมือที่เกี่ยวข้องหลังจบขั้นตอนอินพุต/ผลลัพธ์หลัก
debug redirect
ตรวจ status, URL สุดท้าย, DNS target และสัญญาณ social preview
ตาม redirect chain และ response สุดท้าย
ยืนยัน apex, www และ CNAME ชี้ไปยังเป้าหมายที่ถูกต้อง
แยก query parameter และการเปลี่ยน canonical path
ตรวจ header ความปลอดภัย
ตรวจ header ของ response ร่าง CSP แล้วเช็ก URL และ DNS target ให้ถูกต้อง
ตรวจ status, redirect, header ที่วาง และ warning ของ CSP
แยก origin, path, query และ tracking parameter ก่อนเขียน policy
ยืนยัน hostname resolve ไปยัง deployment ที่กำลังตรวจ
ตรวจความพร้อม search discovery
ก่อนส่ง Search Console หรือ webmaster ให้ตรวจ status สุดท้าย, URL sitemap, robots, canonical/meta และรูป URL
ยืนยัน URL ที่ส่งคืน final 200 บน canonical host ที่ตั้งใจ
ทำความสะอาดรายการ URL ลบรายการซ้ำ และคัดลอกรายงาน search discovery
ยืนยัน rules ของ crawler และ directive sitemap ไม่บล็อกหน้าสาธารณะ แล้วคัดลอกรายงาน crawl
ตรวจ title, description, canonical, robots และ social preview พร้อมกัน แล้วคัดลอกรายงาน crawler
พรีวิวการ์ดแชร์ ตรวจสัญญาณ image และ robots แล้วคัดลอกรายงาน social crawler
ลบ tracking parameter เทียบ canonical candidate ที่สะอาด แล้วคัดลอกรายงาน canonical URL
ก่อนคัดลอก
กรณีผิดพลาดที่พบบ่อย
เครื่องมือที่เกี่ยวข้อง
คู่มือ
เปิดตัวอย่าง รายการตรวจ และเครื่องมือที่เกี่ยวข้องหลังจบขั้นตอนอินพุต/ผลลัพธ์หลัก
https://www.google.comhttp://bobob.apphttps://example.comPreset crawler เปลี่ยนเฉพาะ header ที่ปลอดภัยสำหรับ server-side check นี้ ใช้ Search Console หรือ log เป็นหลักฐาน crawl และ indexing จริง
วาง header ตอบกลับเพื่อตรวจ cache, ความปลอดภัย, cookie และ CORS ก่อนเขียนบันทึก debug
จำนวน header
5
ชื่อซ้ำ
0
header ความปลอดภัย
3
header cookie
0
สแกน header ความปลอดภัยที่นักพัฒนามักตรวจ ก่อนเผยแพร่หรือ debug หน้า public
คะแนน header ความปลอดภัย
3/6
ขาดรายการจำเป็น
1
Strict-Transport-Security
จำเป็น
ปกป้องผู้ใช้ HTTPS จาก protocol downgrade หลังเข้าครั้งแรก
มีContent-Security-Policy
จำเป็น
จำกัด source ของ script, style, image, connection และ frame
มีX-Content-Type-Options
จำเป็น
nosniff ช่วยลดการสับสน MIME type ของ browser
ไม่มีX-Frame-Options / frame-ancestors
แนะนำ
ควบคุมว่าเว็บอื่นฝังหน้านี้ใน frame ได้หรือไม่
มีReferrer-Policy
แนะนำ
จำกัดข้อมูล URL ที่ส่งไปยัง origin อื่น
ไม่มีPermissions-Policy
แนะนำ
จำกัดการเข้าถึงความสามารถ browser เช่น camera, geolocation และ fullscreen
ไม่มีตรวจ Access-Control response headers ก่อนถือว่า preflight error ของ browser เป็น bug ของแอป
Origin policy
ไม่มี
—
Credential policy
ไม่อนุญาต credentials
Methods ที่อนุญาต
—
Headers ที่อนุญาต
—
Vary Origin
ไม่ใช่
—
Preflight status
200
OPTIONS signal
—
ชื่อ header ถูกปรับให้อ่านง่ายเพื่อดูค่าซ้ำและหมวดตรวจสอบ
คัดลอกรายงานที่ปลอดภัยพร้อมคะแนน header รายการจำเป็นที่ขาด note cookie/CORS และ checklist deploy
จำนวน header
5
คะแนน header ความปลอดภัย
3/6
ขาดรายการจำเป็น
1
header cookie
0
CORS
0
Origin policy
ไม่มี
—
OPTIONS signal
—
รวม header ดิบ
ไม่ใช่
ไม่รวม มีเฉพาะ metric, readiness check และบันทึกตรวจสอบ
Checklist deployment
# รายงาน header ความปลอดภัย
- ตรวจเมื่อ: เวลาคัดลอกของ browser
- จำนวน header: 5
- ชื่อซ้ำ: 0
- คะแนน header ความปลอดภัย: 3/6
- ขาดรายการจำเป็น: 1
- header cookie: 0
- CORS: 0
- Origin policy: ไม่มี (—)
- Credential policy: ไม่อนุญาต credentials
- Methods ที่อนุญาต: —
- Headers ที่อนุญาต: —
- Vary Origin: ไม่ใช่
- OPTIONS signal: —
- Preflight status: 200
- รวม header ดิบ: ไม่รวม มีเฉพาะ metric, readiness check และบันทึกตรวจสอบ
## บันทึกตรวจสอบ
- ไม่พบ warning ของ security header ที่ชัดเจน แต่ควรยืนยัน policy ของแอปก่อนเผยแพร่
## บันทึก CORS preflight
- ไม่พบ CORS response headers ถ้าเป็นหน้าปกติไม่เป็นไร แต่ browser API call แบบ cross-origin จะ fail
## ตรวจ header ความปลอดภัย
- Strict-Transport-Security: มี (จำเป็น)
- Content-Security-Policy: มี (จำเป็น)
- X-Content-Type-Options: ไม่มี (จำเป็น)
- X-Frame-Options / frame-ancestors: มี (แนะนำ)
- Referrer-Policy: ไม่มี (แนะนำ)
- Permissions-Policy: ไม่มี (แนะนำ)
## Checklist deployment
- ยืนยันว่า HTTPS page ส่ง Strict-Transport-Security หลัง response production แรก
- ตรวจ source ของ Content-Security-Policy ก่อนเปลี่ยน report-only เป็น enforcement
- ตรวจ Set-Cookie เรื่อง Secure, HttpOnly, SameSite และการทำงานกับ cache
- ตรวจ CORS origin และ credentials กับ public API client ที่ตั้งใจไว้
- รัน public URL check ซ้ำหลังเปลี่ยน CDN, proxy หรือ deployment{
"entries": [
{
"name": "content-type",
"value": "text/html; charset=utf-8",
"categoryKey": "contentHeaderCategory",
"categoryFallback": "Content"
},
{
"name": "cache-control",
"value": "public, max-age=3600",
"categoryKey": "cacheHeaderCategory",
"categoryFallback": "Cache"
},
{
"name": "strict-transport-security",
"value": "max-age=31536000; includeSubDomains",
"categoryKey": "securityHeaderCategory",
"categoryFallback": "Security"
},
{
"name": "content-security-policy",
"value": "default-src 'self'; img-src 'self' https:",
"categoryKey": "securityHeaderCategory",
"categoryFallback": "Security"
},
{
"name": "x-frame-options",
"value": "DENY",
"categoryKey": "securityHeaderCategory",
"categoryFallback": "Security"
}
],
"malformedLines": 0,
"metrics": {
"headerCount": 5,
"duplicateHeaderNames": 0,
"securityHeaders": 3,
"corsHeaders": 0,
"cookieHeaders": 0,
"presentSecurityHeaders": 3,
"securityCheckCount": 6,
"missingRequiredSecurityHeaders": 1
},
"securityChecks": [
{
"key": "hsts",
"label": "Strict-Transport-Security",
"present": true,
"required": true,
"detail": "ปกป้องผู้ใช้ HTTPS จาก protocol downgrade หลังเข้าครั้งแรก"
},
{
"key": "csp",
"label": "Content-Security-Policy",
"present": true,
"required": true,
"detail": "จำกัด source ของ script, style, image, connection และ frame"
},
{
"key": "x-content-type-options",
"label": "X-Content-Type-Options",
"present": false,
"required": true,
"detail": "nosniff ช่วยลดการสับสน MIME type ของ browser"
},
{
"key": "frame-protection",
"label": "X-Frame-Options / frame-ancestors",
"present": true,
"required": false,
"detail": "ควบคุมว่าเว็บอื่นฝังหน้านี้ใน frame ได้หรือไม่"
},
{
"key": "referrer-policy",
"label": "Referrer-Policy",
"present": false,
"required": false,
"detail": "จำกัดข้อมูล URL ที่ส่งไปยัง origin อื่น"
},
{
"key": "permissions-policy",
"label": "Permissions-Policy",
"present": false,
"required": false,
"detail": "จำกัดการเข้าถึงความสามารถ browser เช่น camera, geolocation และ fullscreen"
}
],
"corsPreflight": {
"hasCorsHeaders": false,
"warnings": [
"ไม่พบ CORS response headers ถ้าเป็นหน้าปกติไม่เป็นไร แต่ browser API call แบบ cross-origin จะ fail"
],
"reviewWarnings": [],
"originPolicy": "ไม่มี",
"originValue": "—",
"credentialsPolicy": "ไม่อนุญาต credentials",
"methodsDisplay": "—",
"headersDisplay": "—",
"optionsPolicy": "—",
"varyOriginLabel": "ไม่ใช่",
"statusDisplay": "200",
"metrics": [
{
"label": "Origin policy",
"value": "ไม่มี",
"description": "—"
},
{
"label": "Credential policy",
"value": "ไม่อนุญาต credentials"
},
{
"label": "Methods ที่อนุญาต",
"value": "—"
},
{
"label": "Headers ที่อนุญาต",
"value": "—"
},
{
"label": "Vary Origin",
"value": "ไม่ใช่",
"description": "—"
},
{
"label": "Preflight status",
"value": "200"
},
{
"label": "OPTIONS signal",
"value": "—"
}
]
},
"warnings": []
}สร้าง header Content-Security-Policy ตรวจ source ที่เสี่ยง แล้วส่งเข้า parser header
directive
7
โหมด header
Enforce
Content-Security-Policy: default-src 'self'; script-src 'self'; style-src 'self'; img-src 'self' data:; connect-src 'self'; font-src 'self'; frame-ancestors 'none'ผลลัพธ์พร้อมคัดลอก
ผลลัพธ์จะแสดงที่นี่