view modules/website/templates/https_core_conf.erb @ 155:e661cb2dd942 puppet-3.6

Make sure that we still redirect to non-www if we want it
author IBBoard <dev@ibboard.co.uk>
date Tue, 28 Mar 2017 21:05:12 +0100
parents ff7ebe76c6e9
children 9cf4ebd6d2ba
line wrap: on
line source

Header always set Strict-Transport-Security "max-age=16070400; includeSubDomains"
Header always set X-Xss-Protection "1; mode=block"
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"

RewriteCond %{HTTP_HOST} !=<%= @primary_name %>
RewriteRule ^(.*)$ https://<%= @primary_name %>/$1 [R=301,L]