Security Headers Insertion
Problem this snippet solves: Centralize the security header management for one or more domains on the recommendation of SecurityHeaders.io.
Be warned!! You can really do damage to your availabili...
Published Mar 14, 2016
Version 1.0JRahm
Admin
Joined January 20, 2005
JRahm
Admin
Joined January 20, 2005
P_Kueppers
Sep 28, 2018MVP
Hi Arun,
Im so sorry Im replying so late. I didnt get a notification :(
We are not using the Header for STS. But from the example in the first post do something like:
"Match all of the following conditions": ALL
"Do the following": "Insert" - "http header" - named: "Strict-Transport-Security" with value "max-age=$static::max_age; includeSubDomains"
This should work.
Infos: https://www.keycdn.com/blog/http-security-headers/