Allow apache to control the HSTS setting

This commit is contained in:
Tom Hughes 2018-01-11 19:44:20 +00:00
parent b396c8cbe5
commit d987416901

View file

@ -27,6 +27,7 @@ cookie_policy = {
}
SecureHeaders::Configuration.default do |config|
config.hsts = SecureHeaders::OPT_OUT
config.csp = SecureHeaders::OPT_OUT
config.csp_report_only = csp_policy
config.cookies = cookie_policy