git.gnu.io has moved to IP address 209.51.188.249 -- please double check where you are logging in.

Commit cd42ee7e authored by mmn's avatar mmn

Allow adding preload token to HSTS header

Use by adding this to config.php:

addPlugin('StrictTransportSecurity', array('preloadToken'=>true));
parent 6d728000
......@@ -33,6 +33,7 @@ class StrictTransportSecurityPlugin extends Plugin
{
public $max_age = 15552000;
public $includeSubDomains = false;
public $preloadToken = false;
function __construct()
{
......@@ -44,7 +45,8 @@ class StrictTransportSecurityPlugin extends Plugin
$path = common_config('site', 'path');
if(common_config('site', 'ssl') == 'always' && ($path == '/' || ! $path )) {
header('Strict-Transport-Security: max-age=' . $this->max_age
. ($this->includeSubDomains ? '; includeSubDomains' : ''));
. ($this->includeSubDomains ? '; includeSubDomains' : '')
. ($this->preloadToken ? '; preload' : ''));
}
}
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment