From 56411ca0e10a90d8206508171e3871146bce5351 Mon Sep 17 00:00:00 2001 From: Literallie Date: Fri, 13 Oct 2017 01:09:04 +0200 Subject: Make HSTS behaviour configurable; Fixes #584 --- lib/config/default.js | 6 ++++++ 1 file changed, 6 insertions(+) (limited to 'lib/config') diff --git a/lib/config/default.js b/lib/config/default.js index a14a4294..f4c45e3d 100644 --- a/lib/config/default.js +++ b/lib/config/default.js @@ -7,6 +7,12 @@ module.exports = { urladdport: false, alloworigin: ['localhost'], usessl: false, + hsts: { + enable: true, + maxAgeSeconds: 31536000, + includeSubdomains: true, + preload: true + }, protocolusessl: false, usecdn: true, allowanonymous: true, -- cgit v1.3.1 From 1634d5c567180b072ed4e345b841642f4ea70924 Mon Sep 17 00:00:00 2001 From: Literallie Date: Fri, 13 Oct 2017 01:14:50 +0200 Subject: Add on/off env var for HSTS --- README.md | 1 + app.json | 5 ++++- lib/config/environment.js | 3 +++ 3 files changed, 8 insertions(+), 1 deletion(-) (limited to 'lib/config') diff --git a/README.md b/README.md index 0fecc43b..dd418d69 100644 --- a/README.md +++ b/README.md @@ -154,6 +154,7 @@ Environment variables (will overwrite other server configs) | HMD_S3_SECRET_ACCESS_KEY | no example | AWS secret key | | HMD_S3_REGION | `ap-northeast-1` | AWS S3 region | | HMD_S3_BUCKET | no example | AWS S3 bucket name | +| HMD_HSTS_ENABLE | ` true` | set to enable [HSTS](https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security) if HTTPS is also enabled (default is ` true`) | Application settings `config.json` --- diff --git a/app.json b/app.json index e06720f4..07678ce3 100644 --- a/app.json +++ b/app.json @@ -23,7 +23,10 @@ "description": "Specify database type. See sequelize available databases. Default using postgres", "value": "postgres" }, - + "HMD_HSTS_ENABLE": { + "description": "whether to also use HSTS if HTTPS is enabled", + "required": false + }, "HMD_DOMAIN": { "description": "domain name", "required": false diff --git a/lib/config/environment.js b/lib/config/environment.js index c108a6f9..27b697a0 100644 --- a/lib/config/environment.js +++ b/lib/config/environment.js @@ -8,6 +8,9 @@ module.exports = { port: process.env.HMD_PORT, urladdport: toBooleanConfig(process.env.HMD_URL_ADDPORT), usessl: toBooleanConfig(process.env.HMD_USESSL), + hsts: { + enable: toBooleanConfig(process.env.HMD_HSTS_ENABLE), + }, protocolusessl: toBooleanConfig(process.env.HMD_PROTOCOL_USESSL), alloworigin: process.env.HMD_ALLOW_ORIGIN ? process.env.HMD_ALLOW_ORIGIN.split(',') : undefined, usecdn: toBooleanConfig(process.env.HMD_USECDN), -- cgit v1.3.1 From 6bdc90d6ffd60cf8fe0509eb9fb3b2d47f185c31 Mon Sep 17 00:00:00 2001 From: Literallie Date: Fri, 13 Oct 2017 01:15:35 +0200 Subject: Add env vars for extra HSTS options --- README.md | 3 +++ app.json | 12 ++++++++++++ lib/config/environment.js | 3 +++ 3 files changed, 18 insertions(+) (limited to 'lib/config') diff --git a/README.md b/README.md index dd418d69..8dc82bb4 100644 --- a/README.md +++ b/README.md @@ -155,6 +155,9 @@ Environment variables (will overwrite other server configs) | HMD_S3_REGION | `ap-northeast-1` | AWS S3 region | | HMD_S3_BUCKET | no example | AWS S3 bucket name | | HMD_HSTS_ENABLE | ` true` | set to enable [HSTS](https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security) if HTTPS is also enabled (default is ` true`) | +| HMD_HSTS_INCLUDE_SUBDOMAINS | `true` | set to include subdomains in HSTS (default is `true`) | +| HMD_HSTS_MAX_AGE | `31536000` | max duration in seconds to tell clients to keep HSTS status (default is a year) | +| HMD_HSTS_PRELOAD | `true` | whether to allow preloading of the site's HSTS status (e.g. into browsers) | Application settings `config.json` --- diff --git a/app.json b/app.json index 07678ce3..1de6b7db 100644 --- a/app.json +++ b/app.json @@ -27,6 +27,18 @@ "description": "whether to also use HSTS if HTTPS is enabled", "required": false }, + "HMD_HSTS_MAX_AGE": { + "description": "max duration, in seconds, to tell clients to keep HSTS status", + "required": false + }, + "HMD_HSTS_INCLUDE_SUBDOMAINS": { + "description": "whether to tell clients to also regard subdomains as HSTS hosts", + "required": false + }, + "HMD_HSTS_PRELOAD": { + "description": "whether to allow at all adding of the site to HSTS preloads (e.g. in browsers)", + "required": false + }, "HMD_DOMAIN": { "description": "domain name", "required": false diff --git a/lib/config/environment.js b/lib/config/environment.js index 27b697a0..40b7e09f 100644 --- a/lib/config/environment.js +++ b/lib/config/environment.js @@ -10,6 +10,9 @@ module.exports = { usessl: toBooleanConfig(process.env.HMD_USESSL), hsts: { enable: toBooleanConfig(process.env.HMD_HSTS_ENABLE), + maxAgeSeconds: process.env.HMD_HSTS_MAX_AGE, + includeSubdomains: toBooleanConfig(process.env.HMD_HSTS_INCLUDE_SUBDOMAINS), + preload: toBooleanConfig(process.env.HMD_HSTS_PRELOAD) }, protocolusessl: toBooleanConfig(process.env.HMD_PROTOCOL_USESSL), alloworigin: process.env.HMD_ALLOW_ORIGIN ? process.env.HMD_ALLOW_ORIGIN.split(',') : undefined, -- cgit v1.3.1