FIX: HSTS header was overwrote by Referrer-Policy add_header
authorRafael dos Santos Silva <xfalcox@gmail.com>
Fri, 14 Jul 2017 02:37:48 +0000 (23:37 -0300)
committerRafael dos Santos Silva <xfalcox@gmail.com>
Fri, 14 Jul 2017 02:37:48 +0000 (23:37 -0300)
templates/web.ssl.template.yml

index 76b600eac024815f2eb8b29a4c5c478a56f00967..681abdc8bc90173fdb233b14d7c09a78f01348fd 100644 (file)
@@ -37,3 +37,9 @@ run:
        if ($http_host != $$ENV_DISCOURSE_HOSTNAME) {
           rewrite (.*) https://$$ENV_DISCOURSE_HOSTNAME$1 permanent;
        }
+  - replace:
+     filename: "/etc/nginx/conf.d/discourse.conf"
+     from: /add_header Referrer-Policy 'no-referrer-when-downgrade';/m
+     to: |
+       add_header Referrer-Policy 'no-referrer-when-downgrade';
+       add_header Strict-Transport-Security 'max-age=31536000'; # remember the certificate for a year and automatically connect to HTTPS for this domain