-
Notifications
You must be signed in to change notification settings - Fork 63
Open
Description
I installed opencloud-compose with keycloak, ldap, traefik, collabora enabled as shown in the example file.
Traefik doesn't seem to enforce HSTS on any of the domains. Keycloak does on its own domain, but this doesn't provide any protection against attacks because the http request has already been made.
Should be simple to add HSTS with options to disable for dev/local use?
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels