-
Notifications
You must be signed in to change notification settings - Fork 83
Add middleware for setting HSTS headers #387
Conversation
/assign @icco |
@@ -130,6 +130,12 @@ func realMain(ctx context.Context) error { | |||
} | |||
rateLimit := httplimiter.Handle | |||
|
|||
// Install HSTS headers in production | |||
if !config.DevMode { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
guessing this won't matter as non-browsers will ignore...
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
but also no harm
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
You don't want to set it in dev because localhost w/ hsts doesn't work.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think Mike was saying that no one will call the API in the browser so it probably doesn't matter
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: mikehelmick, sethvargo The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Fixes GH-381
Release Note