Middleware: Don't require HTTPS for HSTS headers to be emitted (#35147)

Grafana itself may not be serving content over HTTPS, but it may be
behind a transparent proxy which does.

Fixes #26770.  Based on #26868.
This commit is contained in:
Alex Vandiver
2022-01-28 07:23:28 +01:00
committed by GitHub
parent 7b476c19c2
commit 844b194f5b
5 changed files with 2 additions and 5 deletions
+1 -1
View File
@@ -546,7 +546,7 @@ mitigate the risk of [Clickjacking](https://owasp.org/www-community/attacks/Clic
### strict_transport_security
Set to `true` if you want to enable HTTP `Strict-Transport-Security` (HSTS) response header. This is only sent when HTTPS is enabled in this configuration. HSTS tells browsers that the site should only be accessed using HTTPS.
Set to `true` if you want to enable HTTP `Strict-Transport-Security` (HSTS) response header. Only use this when HTTPS is enabled in your configuration, or when there is another upstream system that ensures your application does HTTPS (like a frontend load balancer). HSTS tells browsers that the site should only be accessed using HTTPS.
### strict_transport_security_max_age_seconds