Skip to content

Conversation

@skord
Copy link
Member

@skord skord commented Jul 8, 2025

Summary

• Add Strict-Transport-Security header to all HTTPS responses from the frontend
• Improves security by preventing protocol downgrade attacks
• Header includes includeSubDomains directive for comprehensive protection

Test plan

  • Verify HSTS header is present in HTTP responses
  • Confirm no impact on existing functionality

Closes https://github.com/estuary/security/issues/382


This change is Reviewable

@skord skord requested a review from jgraettinger July 8, 2025 15:43
@skord skord self-assigned this Jul 8, 2025
@skord skord force-pushed the mdanko/add-hsts-header branch from 90d6488 to 726a8a9 Compare July 8, 2025 17:03
@jgraettinger
Copy link
Member

Do local stacks continue to function correctly with this change?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants