diff options
author | Frédéric Guillot <fred@kanboard.net> | 2014-09-20 15:35:17 +0200 |
---|---|---|
committer | Frédéric Guillot <fred@kanboard.net> | 2014-09-20 15:35:17 +0200 |
commit | eeb4688dcc7caafeaa020a3cd9d78d18aea30353 (patch) | |
tree | 80887432a5425cbba01d40e4add7a4dc1125583d /app/Controller/Base.php | |
parent | de225f401d036c153a4dfe36e7936b877e77d6d5 (diff) |
Add configuration option to enable/disable 'Strict-Transport-Security' HTTP header
Diffstat (limited to 'app/Controller/Base.php')
-rw-r--r-- | app/Controller/Base.php | 5 |
1 files changed, 4 insertions, 1 deletions
diff --git a/app/Controller/Base.php b/app/Controller/Base.php index 8f822f3d..e9957bbd 100644 --- a/app/Controller/Base.php +++ b/app/Controller/Base.php @@ -116,9 +116,12 @@ abstract class Base $this->response->csp(array('style-src' => "'self' 'unsafe-inline'")); $this->response->nosniff(); $this->response->xss(); - $this->response->hsts(); $this->response->xframe(); + if (ENABLE_HSTS) { + $this->response->hsts(); + } + // Load translations $language = $this->config->get('language', 'en_US'); if ($language !== 'en_US') Translator::load($language); |