In my nginx.conf file I define a header on the http level
add_header Strict-Transport-Security "max-age=86400; includeSubDomains" always;
When I check the network response headers in chrome dev tools, it shows 2 of those headers
strict-transport-security: max-age=15552000; includeSubDomains
strict-transport-security: max-age=86400; includeSubDomains
Notes:
add_header once. nginx.conf file in the nginx-docker imageQuestions:
thanks @RichardSmith for the great comment.
nginx -T is really great for testing, as it will show the full configuration (with all includes, etc.)curl -I also showed both headers (to make sure that the browser does not used any cache, etc.)nginx.confIf you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With