Skip to content

SEC-3039: Emit error on startup when using HSTS together with require-channel="http" #3245

@spring-projects-issues

Description

@spring-projects-issues

Thomas Timbul (Migrated from SEC-3039) said:

Using HSTS and specifying require-channel="http" anywhere amounts to invalid configuration. Doing so would break a site.

In such case a clear and prominent error should be emitted on startup pointing the user to the documentation, which should be improved as per https://jira.spring.io/browse/SEC-3038
Container startup should fail with an Exception to prevent this misconfiguration rather than just showing a warning.

Metadata

Metadata

Assignees

No one assigned

    Labels

    type: enhancementA general enhancementtype: jiraAn issue that was migrated from JIRA

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions