-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
Closed
nextcloud/documentation
#462Labels
Milestone
Description
An article on your site contains a recommended HSTS header value that includes preload in the only example: https://docs.nextcloud.com/server/9/admin_manual/configuration_server/harden_server.html
This is going to shoot developers in the foot, and also doesn't guarantee preloading unless someone submits the site to hstspreload.org separetely. See https://hstspreload.org/#opt-in (and chromium/hstspreload.org#68)
Could you update your guide to remove it, or list two examples, the second of which explains preloading and links to hstspreload.org?
(I tried pinging at https://twitter.com/Nextclouders/status/805161033975398400 and emailing the contact address on your site, but that hasn't resulted in a response over the last 6 months.)
Reactions are currently unavailable