summaryrefslogtreecommitdiff
path: root/src/server/index.ts
diff options
context:
space:
mode:
authorsyuilo <syuilotan@yahoo.co.jp>2018-10-17 04:15:41 +0900
committersyuilo <syuilotan@yahoo.co.jp>2018-10-17 04:15:41 +0900
commit61f86dcb2b9cec8d55cf6a77f592ba359ff8b52b (patch)
tree8b675875925bb911fa5339e3f220c0cc0a56c939 /src/server/index.ts
parentAdd some messaging API tests (diff)
downloadsharkey-61f86dcb2b9cec8d55cf6a77f592ba359ff8b52b.tar.gz
sharkey-61f86dcb2b9cec8d55cf6a77f592ba359ff8b52b.tar.bz2
sharkey-61f86dcb2b9cec8d55cf6a77f592ba359ff8b52b.zip
Resolve #2923
Allow option to disable sending HSTS headers even if https:// is used in url
Diffstat (limited to 'src/server/index.ts')
-rw-r--r--src/server/index.ts2
1 files changed, 1 insertions, 1 deletions
diff --git a/src/server/index.ts b/src/server/index.ts
index e9b2e2440a..66a1d97d29 100644
--- a/src/server/index.ts
+++ b/src/server/index.ts
@@ -41,7 +41,7 @@ app.use(compress({
// HSTS
// 6months (15552000sec)
-if (config.url.startsWith('https')) {
+if (config.url.startsWith('https') && !config.disableHsts) {
app.use(async (ctx, next) => {
ctx.set('strict-transport-security', 'max-age=15552000; preload');
await next();