Mercurial > prosody-modules
view mod_strict_https/README.markdown @ 3693:0fb12a4b6106
auth_token: Various updates, see below.
* Defer to usermanager when testing the password
* Because of this, don't assume the realm is available when verifying the token
* Fix linting errors
By using the `usermanager`, other modules can now ask the user manager to verify token credentials.
author | JC Brand <jc@opkode.com> |
---|---|
date | Thu, 03 Oct 2019 12:13:44 +0200 |
parents | 4d73a1a6ba68 |
children | 0c8e6269ea38 |
line wrap: on
line source
--- labels: summary: HTTP Strict Transport Security ... Introduction ============ This module implements [HTTP Strict Transport Security](https://tools.ietf.org/html/rfc6797) and responds to all non-HTTPS requests with a `301 Moved Permanently` redirect to the HTTPS equivalent of the path. Configuration ============= Add the module to the `modules_enabled` list and optionally configure the specific header sent. modules_enabled = { ... "strict_https"; } hsts_header = "max-age=31556952" Compatibility ============= ------- -------------- trunk Works 0.9 Works 0.8 Doesn't work ------- --------------