4 ms·
You should probably add -> "add_header Strict-Transport-Security max-age=31536000;" to your nginx config.
by lifeeth_ 13y ago
You should probably add -> "add_header Strict-Transport-Security max-age=31536000;" to your nginx config.
- RKearney 13y agoBad idea. Then anyone who accesses it over HTTPS won't be able to use HTTP anymore and HTTPS requires a paid plan of some sort. Ideally they should be on separate domains, at which point HSTS would be more suited.
- lifeeth_ 13y agoPaid plan for API access I guess - hoping one wont use the same environment for both. I meant this for the stripe frame which kicks in, cant really trust an https frame that has a start from http.