Enable HTTP Strict Transport Security (HSTS)
Nobody has claimed this yet.
- Dominant language
- CSS
- Stars
- 99
- Forks
- 708
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 22
Description
Description:
In the documentation "Security Guidelines for a Production Deployment" [1] are the security guidelines for the API-M runtime [2]. But the part where it says "ensure HTTP Strict Transport Security (HSTS) is enabled for all enhanced applications on your server" does not have a link to a page (for example [3]) explaining how to "Enable HTTP Strict Transport Security (HSTS)".
I ask for time to correct the docs by adding the link to a page explaining how to "Enabling HTTP Strict Transport Security (HSTS) headers". A good example of documents that took care of this is [4]
[1]https://apim.docs.wso2.com/en/4.1.0/install-and-setup/setup/deployment-best-practices/security-guidelines-for-production-deployment/
[2]https://apim.docs.wso2.com/en/4.1.0/install-and-setup/setup/deployment-best-practices/security-guidelines-for-production-deployment/#api-m- runtime security
[3]https://docs.wso2.com/display/ADMIN44x/Securing+Carbon+Applications#SecuringCarbonApplications-EnablingHTTPStrictTransportSecurity(HSTS)Headers
[4] https://is.docs.wso2.com/en/5.10.0/administer/product-level-security-guidelines/#hsts
Suggested Labels:
API-M-4.1.0, Type/Doc
Affected Product Version:
APIM 4.1.0
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the "Security Guidelines for a Production Deployment" page for APIM 4.1.0, especially the API-M runtime security section referenced in the issue. Add a link explaining how to enable HSTS headers, using the linked examples as guidance, then verify that the documentation points readers to the intended HSTS instructions.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 65/100