[ https://issues.apache.org/jira/browse/SOLR-15578?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17550548#comment-17550548 ]
Shawn Heisey commented on SOLR-15578: ------------------------------------- Maybe turn on the header by default in the https config and then provide an option to turn it off to avoid the testing problem that [~houston] mentions? >From what I can tell, the proposed changes only affect redirects, the HSTS >header wouldn't be sent on all responses that Solr sends normally via https, >which I believe is required to properly implement the header. > Add Support for HSTS Security Protocol > -------------------------------------- > > Key: SOLR-15578 > URL: https://issues.apache.org/jira/browse/SOLR-15578 > Project: Solr > Issue Type: Improvement > Components: Server, v2 API > Affects Versions: 9.0 > Reporter: Marcus Eagan > Priority: Major > Time Spent: 2h > Remaining Estimate: 0h > > A committer raised the idea of a supporting HSTS protocol and I think it is a > good idea. We can add it somewhat easily as an option. -- This message was sent by Atlassian Jira (v8.20.7#820007) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@solr.apache.org For additional commands, e-mail: issues-h...@solr.apache.org