wso2 / wso2/docs-apim

Enable HTTP Strict Transport Security (HSTS)

Open Beginner friendly
#7,036 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
CSS
Stars
99
Forks
708
Avg merge
1d 7h
Merged PRs (30d)
22

Description

Description:
In the documentation "Security Guidelines for a Production Deployment" [1] are the security guidelines for the API-M runtime [2]. But the part where it says "ensure HTTP Strict Transport Security (HSTS) is enabled for all enhanced applications on your server" does not have a link to a page (for example [3]) explaining how to "Enable HTTP Strict Transport Security (HSTS)".

I ask for time to correct the docs by adding the link to a page explaining how to "Enabling HTTP Strict Transport Security (HSTS) headers". A good example of documents that took care of this is [4]

[1]https://apim.docs.wso2.com/en/4.1.0/install-and-setup/setup/deployment-best-practices/security-guidelines-for-production-deployment/
[2]https://apim.docs.wso2.com/en/4.1.0/install-and-setup/setup/deployment-best-practices/security-guidelines-for-production-deployment/#api-m- runtime security
[3]https://docs.wso2.com/display/ADMIN44x/Securing+Carbon+Applications#SecuringCarbonApplications-EnablingHTTPStrictTransportSecurity(HSTS)Headers
[4] https://is.docs.wso2.com/en/5.10.0/administer/product-level-security-guidelines/#hsts

Suggested Labels:
API-M-4.1.0, Type/Doc

Affected Product Version:
APIM 4.1.0

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the "Security Guidelines for a Production Deployment" page for APIM 4.1.0, especially the API-M runtime security section referenced in the issue. Add a link explaining how to enable HSTS headers, using the linked examples as guidance, then verify that the documentation points readers to the intended HSTS instructions.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
65/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.