-
Type: Improvement
-
Status: Resolved
-
Priority: Minor
-
Resolution: Fixed
-
Affects Version/s: None
-
Component/s: Distribution / Installers
-
Release Notes Summary:The HSTS header is enabled by default when HTTPS is in use
-
Impact type:Configuration Change
-
Upgrade notes:
-
Sprint:nxcore 10.1.1
-
Story Points:1
The HSTS (HTTP Strict Transport Security) header should be enabled by default when HTTPS is in use.
Let's also add a nuxeo.conf property to allow disabling this if a customer wants both HTTP and HTTPS, but the default should be that HSTS is enabled.