Skip to content

Commit

Permalink
Bugfix: add HSTS header to avoid security issue (#631)
Browse files Browse the repository at this point in the history
<!-- Please provide brief information about the PR, what it contains &
its purpose, new behaviors after the change. And let us know here if you
need any help: https://github.com/microsoft/HydraLab/issues/new -->

## Description

<!-- A few words to explain your changes -->

### Linked GitHub issue ID: #  

## Pull Request Checklist
<!-- Put an x in the boxes that apply. This is simply a reminder of what
we are going to look for before merging your code. -->

- [ ] Tests for the changes have been added (for bug fixes / features)
- [ ] Code compiles correctly with all tests are passed.
- [x] I've read the [contributing
guide](https://github.com/microsoft/HydraLab/blob/main/CONTRIBUTING.md#making-changes-to-the-code)
and followed the recommended practices.
- [x] [Wikis](https://github.com/microsoft/HydraLab/wiki) or
[README](https://github.com/microsoft/HydraLab/blob/main/README.md) have
been reviewed and added / updated if needed (for bug fixes / features)

### Does this introduce a breaking change?
*If this introduces a breaking change for Hydra Lab users, please
describe the impact and migration path.*

- [ ] Yes
- [ ] No

## How you tested it
*Please make sure the change is tested, you can test it by adding UTs,
do local test and share the screenshots, etc.*


Please check the type of change your PR introduces:
- [x] Bugfix
- [ ] Feature
- [ ] Technical design
- [ ] Build related changes
- [ ] Refactoring (no functional changes, no api changes)
- [ ] Code style update (formatting, renaming) or Documentation content
changes
- [ ] Other (please describe): 

### Feature UI screenshots or Technical design diagrams
*If this is a relatively large or complex change, kick it off by drawing
the tech design with PlantUML and explaining why you chose the solution
you did and what alternatives you considered, etc...*
  • Loading branch information
zhou9584 committed Dec 12, 2023
1 parent 6216dda commit 78e624e
Showing 1 changed file with 5 additions and 2 deletions.
7 changes: 5 additions & 2 deletions center/deploy_startup/nginx.conf
Original file line number Diff line number Diff line change
Expand Up @@ -51,11 +51,14 @@ http {
server {
listen 80;
server_name localhost;

# for HSTS security header
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload";
#charset koi8-r;

#access_log logs/host.access.log main;

location = / {
return 301 /portal/index.html;
}
location / {
proxy_pass http://localhost:9886;
proxy_set_header Host $http_host;
Expand Down

0 comments on commit 78e624e

Please sign in to comment.