Giter VIP home page Giter VIP logo

cloud_hsts's Introduction

HTTP Strict Transport Security

GitHub All Releases GitHub license

The only purpose of this Nextcloud application is to add the Strict-Transport-Security header to installations which do not support header configuration via a server configuration file (e.g. .htaccess).

How to install

  1. Download this archive, extract it to apps/ and enable it or install via app store
  2. Visit your page via https
  3. You're done

If you like, you can verify that everything is working as expected with the Security Header Scan.

Configuration

You can change the HSTS header with the following Nextcloud system options (add them to config/config.php)

  • hsts.maxAge (number) expiry time in seconds; default=15768000 (half a year)
  • hsts.includeSubDomains (boolean) apply HSTS rule to all subdomains as well; default=false
  • hsts.preload (boolean) allow adding the domain to the HSTS preload list; default=false

cloud_hsts's People

Contributors

dependabot[bot] avatar indigo744 avatar marcelwaldvogel avatar nicomaha avatar sualko avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar

cloud_hsts's Issues

HSTS Header doesn’t exist for Nextcloud 24 (and 25)

Hello,

I want to migrate to the 24th branch of Nextcloud, but I have this message since several months:
2022-09-02_18-12-29
HSTS Header doesn’t exist for Nextcloud 24.

I have ask my web hosting (Infomaniak) and I have no headers activated.

I have deactivate the module this morning, to test my Nextcloud without the module.

I have two choice now:
— wait since HSTS Header create a new version that support Nextcloud 24, than migrate to it
— desactivate the apps and migrate, and perhaps have a security problem

What shloud I do, please? Do you can do somethings for Nextcloud user that have shared server?

Thanks.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.