Re: ?= HSTS (or custom headers)

Rick O'Sullivan <[email protected]> Tue, 31 Dec 2019 13:51:17 -0500
Newsgroups gmane.comp.web.pound.general
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============7877542948132568731==
Content-Type: multipart/alternative;
 boundary="------------1D5427EA421AF6F36D4A2F87"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------1D5427EA421AF6F36D4A2F87
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit

I've merged Frank's HSTS patch to add the StrictTransportSecurity 
directive into my fork at https://github.com/patrodyne/pound

On 12/30/19 3:13 AM, Frank Schmirler wrote:
> Am Donnerstag, 26. Dezember 2019 14:57 CET, [email protected] schrieb:
>> Does Pound support HSTS ?
>>
>> Does Pound support adding headers to the outgong web response?
>> I see the "AddHeader" option which apparently adds headers to the
>> incoming request (to the back-end server), but I don't see any options
>> that let me add headers to the outgoing response (back to the client).
> I've attached the HSTS patch I posted years ago (updated to pound 2.8). With the patch you can add the following directive to your config at service level:
> StrictTransportSecurity <SECONDS>
>
> Best regards,
> Frank
>


--------------1D5427EA421AF6F36D4A2F87
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    I've merged Frank's HSTS patch to add the StrictTransportSecurity
    directive into my fork at <a class="moz-txt-link-freetext" href="https://github.com/patrodyne/pound">https://github.com/patrodyne/pound</a><br>
    <br>
    <div class="moz-cite-prefix">On 12/30/19 3:13 AM, Frank Schmirler
      wrote:<br>
    </div>
    <blockquote type="cite" cite="mid:2b-5e09b180-3-7ae77d00@258145686">
      <pre class="moz-quote-pre" wrap="">Am Donnerstag, 26. Dezember 2019 14:57 CET, <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a> schrieb: 
</pre>
      <blockquote type="cite">
        <pre class="moz-quote-pre" wrap="">Does Pound support HSTS ?

Does Pound support adding headers to the outgong web response?
I see the "AddHeader" option which apparently adds headers to the
incoming request (to the back-end server), but I don't see any options
that let me add headers to the outgoing response (back to the client).
</pre>
      </blockquote>
      <pre class="moz-quote-pre" wrap="">
I've attached the HSTS patch I posted years ago (updated to pound 2.8). With the patch you can add the following directive to your config at service level:
StrictTransportSecurity &lt;SECONDS&gt;

Best regards,
Frank
</pre>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
    </blockquote>
    <br>
  </body>
</html>

--------------1D5427EA421AF6F36D4A2F87--


--===============7877542948132568731==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

-- 
pound mailing list
[email protected]
https://admin.hostpoint.ch/mailman/listinfo/pound_apsis.ch

--===============7877542948132568731==--