Comments (2)
I don't get it.
What headers that come by default from the lolisafe server, that prevents you from setting other headers such as the ones you mentioned above (Strict-Transport-Security)?
I also use Nginx config to set those headers for safe.fiery.me.
The lolisafe server only sets Cache-Control and Access-Control-Allow-Origin, but only when you choose to enable them from the config (other than some defaults set by Express).
Even the defaults set by Express can be overridden from Nginx, if you so desire. At least that's what I did for my installation.
from lolisafe.
Whoops, sorry about that. It seems mine was overwritten by Cloudflare as I had HSTS configured there. That's why I didn't notice Helmet would add the header by default.
You'd have needed to compile nginx with ngx_headers_more module to override the header set by Helmet through Nginx, otherwise.
from lolisafe.
Related Issues (20)
- migrating from chibisafe to lolisafe results in missing columns HOT 5
- Dependency Dashboard
- database from v4 chibisafe is not compatible with this fork
- How to access the API HOT 2
- Cannot access files uploaded to lolisafe HOT 4
- Error Code 0. HOT 5
- TypeError: Cannot read properties of undefined (reading 'hasher') HOT 9
- Add more upload size for certain groups. HOT 3
- sqlite3 CXXABI_1.3.8 not found error HOT 4
- Problem with the waveform HOT 4
- Docker Image building error HOT 2
- Are the files supposed to served on both domains? HOT 25
- Make usernames case-sensitive. HOT 1
- Audio and video not downloading/working properly HOT 17
- Reset password HOT 1
- Users get their own folder HOT 1
- Page not loading properly HOT 4
- Promote to superadmin HOT 2
- Chunked uploads fail when coming from IPv6 addresses HOT 2
- Is there a way to restrict accessing files only to logged in users? HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from lolisafe.