Skip to content

Commit 0483b29

Browse files
committed
Add 'always' parameter ensures that the header is set for all responses
1 parent a1fc352 commit 0483b29

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

config/nginx.conf

+4-4
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ server {
3232
ssl_certificate_key /etc/letsencrypt/live/api.rubyonrails.org/privkey.pem; # managed by Certbot
3333
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
3434
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
35-
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains;"; # config to enable HSTS
35+
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains;" always; # config to enable HSTS
3636

3737
}
3838

@@ -70,7 +70,7 @@ server {
7070
ssl_certificate_key /etc/letsencrypt/live/api.rubyonrails.org/privkey.pem; # managed by Certbot
7171
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
7272
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
73-
73+
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains;" always; # config to enable HSTS
7474
}
7575

7676
#
@@ -90,7 +90,7 @@ server {
9090
ssl_certificate_key /etc/letsencrypt/live/api.rubyonrails.org/privkey.pem; # managed by Certbot
9191
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
9292
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
93-
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains;"; # config to enable HSTS
93+
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains;" always; # config to enable HSTS
9494

9595
}
9696

@@ -112,7 +112,7 @@ server {
112112
ssl_certificate_key /etc/letsencrypt/live/api.rubyonrails.org/privkey.pem; # managed by Certbot
113113
include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
114114
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot
115-
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains;"; # config to enable HSTS
115+
add_header Strict-Transport-Security "max-age=63072000; includeSubdomains;" always; # config to enable HSTS
116116

117117
}
118118

0 commit comments

Comments
 (0)