Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add support for including a Strict-Transport-Security header (for use only when a proxy or load balancer is handling TLS/SSL) (was PR # 85 for drdrew42 repo) #6

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions lib/RenderApp.pm
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,16 @@ sub startup {
$ENV{baseURL} = $ENV{SITE_HOST} . $ENV{baseURL} unless ( $ENV{baseURL} =~ m|^https?://| );
$ENV{formURL} = $ENV{baseURL} . $ENV{formURL} unless ( $ENV{formURL} =~ m|^https?://| );

# Handle optional Strict-Transport-Security header
if (my $HSTS_HEADER = $self->config('HSTS_HEADER')) {
$self->hook(before_dispatch => sub {
my $c = shift;
$c->res->headers->header(
'Strict-Transport-Security' => $HSTS_HEADER
);
});
}

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Rather than adding a separate before_dispatch hook to the CORS settings, just use the same hook. We don't want a bunch of separate hooks like this. Although, I don't think either of these belong in the renderer code. This is something that should be set by the proxy.

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm not using a proxy. The renderer seems to work reasonably well without one, and in my use case is behind an AWS application load balancer which does SSL offloading.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You should be running hypnotoad behind some sort of proxy. In any case, see my later comment.

# Handle optional CORS settings
if (my $CORS_ORIGIN = $self->config('CORS_ORIGIN')) {
die "CORS_ORIGIN ($CORS_ORIGIN) must be an absolute URL or '*'"
Expand Down