Middleware: Don't require HTTPS for HSTS headers to be emitted (#35147)

Grafana itself may not be serving content over HTTPS, but it may be
behind a transparent proxy which does.

Fixes #26770.  Based on #26868.
This commit is contained in:
Alex Vandiver
2022-01-28 07:23:28 +01:00
committed by GitHub
parent 7b476c19c2
commit 844b194f5b
5 changed files with 2 additions and 5 deletions
-1
View File
@@ -68,7 +68,6 @@ func TestMiddleWareSecurityHeaders(t *testing.T) {
sc.fakeReq("GET", "/api/").exec()
assert.Equal(t, "max-age=64000; preload; includeSubDomains", sc.resp.Header().Get("Strict-Transport-Security"))
}, func(cfg *setting.Cfg) {
cfg.Protocol = setting.HTTPSScheme
cfg.StrictTransportSecurity = true
cfg.StrictTransportSecurityMaxAge = 64000
})