Add missing max-age param to HPKP
This commit is contained in:
parent
7e9a17266b
commit
2d00917ff2
@ -85,10 +85,10 @@ app.use(function *(next) {
|
|||||||
// Set HTTP response headers
|
// Set HTTP response headers
|
||||||
app.use(function *(next) {
|
app.use(function *(next) {
|
||||||
if (util.isTrue(config.server.upgradeHTTPS)) {
|
if (util.isTrue(config.server.upgradeHTTPS)) {
|
||||||
this.set('Strict-Transport-Security', 'max-age=31536000');
|
this.set('Strict-Transport-Security', 'max-age=16070400');
|
||||||
}
|
}
|
||||||
if (config.server.publicKeyPin) {
|
if (config.server.publicKeyPin) {
|
||||||
this.set('Public-Key-Pins', 'pin-sha256="' + config.server.publicKeyPin + '"');
|
this.set('Public-Key-Pins', 'pin-sha256="' + config.server.publicKeyPin + '"; max-age=16070400');
|
||||||
}
|
}
|
||||||
this.set('Access-Control-Allow-Origin', '*');
|
this.set('Access-Control-Allow-Origin', '*');
|
||||||
this.set('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');
|
this.set('Access-Control-Allow-Methods', 'GET, POST, PUT, DELETE, OPTIONS');
|
||||||
|
Loading…
Reference in New Issue
Block a user