NginxProxyManager / NginxProxyManager/nginx-proxy-manager
Strange HSTS configuration
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 34.2k
- Forks
- 3.9k
- Avg merge
- 21h 12m
- Merged PRs (30d)
- 20
Description
Checklist
- Have you pulled and found the error with
jc21/nginx-proxy-manager:latestdocker image?- Yes
- Are you sure you're not using someone else's docker image?
- Yes
- Have you searched for similar issues (both open and closed)?
- Yes
Describe the bug
When testing the SSL with online tools I'm getting neggative points for the HSTS configuration. Online tools used:
Strange HSTS configuration. W
Nginx Proxy Manager Version
v2.12.3 © 2024 jc21.com. Theme by Tabler
To Reproduce
Steps to reproduce the behavior:
- Set up a proxy host
- test your website with the tools mentioned above
- See error
Expected behavior
Enabling HSTS should not give an "Server sent invalid HSTS policy." error.
Operating System
TrueNAS SCALE 25.04 Fangtooth
Linux Kernel 6.12.15
Docker Engine 27.5.0
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the issue with the proxy host and SSL settings described, then inspect the HSTS response using SSL Labs or Mozilla Observatory. Trace where Nginx Proxy Manager generates the HSTS configuration and verify the resulting policy against the reported invalid-policy error. Done means enabling HSTS produces a valid policy in both tools.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- docker, nginx
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100