We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

Implement HSTS ?

How Do I?

Okapi Creative's avatar
Okapi Creative
382 posts
about 6 months ago
Okapi Creative's avatar Okapi Creative

Need some pointers on how to enable HTTP Strict-Transport-Security response header in EE6.

Are there any docs out there or tutorials?

Also need to put a Content-Security-Policy header - can anyone point me in right direction please?

Thanks!

       
Ahoena12's avatar
Ahoena12
4 posts
5 months ago
Ahoena12's avatar Ahoena12

To enable the HTTP Strict-Transport-Security (HSTS) response header in EE6, you can typically configure it in your web server settings (like Apache or Nginx) or directly in your application’s configuration files. For detailed guidance, you might find the official documentation for EE6 or web server tutorials helpful.

For the Content-Security-Policy (CSP) header, you can also set this in your web server configuration or application settings. Look for tutorials specific to your server type or the EE6 documentation for examples on how to implement these security headers effectively.

       
Okapi Creative's avatar
Okapi Creative
382 posts
5 months ago
Okapi Creative's avatar Okapi Creative

Thanks Ahoena12 - I’ve tried it with a Meta tag and it keeps breaking everything. Need to look into it more deeply

       
Tom Jaeger's avatar
Tom Jaeger
449 posts
5 months ago
Tom Jaeger's avatar Tom Jaeger

Howdy,

Might also be worth taking a look at Hop CSP Header

We talked about this briefly internally and it’s likely we’ll add this to the http_header core add-on in V 7

Cheers,

-Tom Jaeger

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.