Remove duplicate HSTS header on Apache if mod_headers is loaded

On Apache httpd, ./.htaccess sets HSTS if mod_headers is loaded, but though ./v/0.0.0/include.php does the same if envvar "HTTPS" is set, resulting in duplicate and thus invalid HSTS headers. One needs to go.
This commit is contained in:
Veit 2022-04-19 23:09:20 +02:00
parent eff357dc8e
commit 260ef6dc9d

View file

@ -23,7 +23,7 @@
# Header set Cache-Control "public, max-age=31536000"
# Header set Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval'; img-src 'self' data:; style-src 'self' 'unsafe-inline'"
# Header set Referrer-Policy "no-referrer"
Header set Strict-Transport-Security "max-age=31536000"
# Header set Strict-Transport-Security "max-age=31536000"
Header set imagetoolbar "no"
# Header set X-Content-Type-Options "nosniff"
# Header set X-Frame-Options "DENY"