HSTS Preloading Should Be Opt-In
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 38/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Estancado
- Stack tecnológico
- nginx, php, wordpress
- Área
- infrastructure, security
Línea de trabajo
Empieza inspeccionando /etc/nginx/conf.d/spec-settings.conf en el contenedor de WordPress y compara su directiva Strict-Transport-Security con las indicaciones de hstspreload.org. Revisa la solución alternativa documentada en /home/dev/startup.sh. Se considera completado cuando la precarga de HSTS y la cobertura de subdominios ya no están habilitadas inesperadamente, y el opt-in requerido o la documentación quedan claros.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Hey there 👋,
per the hstspreload.org site:
If you maintain a project that provides HTTPS configuration advice or provides an option to enable HSTS, do not include the preload directive by default. We get regular emails from site operators who tried out HSTS this way, only to find themselves on the preload list by the time they find they need to remove HSTS to access certain subdomains. Removal tends to be slow and painful for those sites.
Projects that support or advise about HSTS and HSTS preloading should ensure that site operators understand the long-term consequences of preloading before they turn it on for a given domain. They should also be informed that they need to meet additional requirements and submit their site to hstspreload.org to ensure that it is successfully preloaded (i.e. to get the full protection of the intended configuration).
The WordPress container image used by the 'WordPress on App Service' marketplace item does currently enable HSTS by default. If someone doesn't notice this, they can get really caught of guard, since now their domain and (internal) subdomains require https which browsers will remember for 1 year.
Enabling HSTS by default is maybe okay, but I don't think it should include subdomains and enable preloading, since that can have a huge impact.
$ docker run --rm --entrypoint /bin/sh mcr.microsoft.com/appsvc/wordpress-alpine-php -c 'grep -i strict-transport-security /etc/nginx/co
nf.d/spec-settings.conf'
add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload';
At the very least this should be documented somewhere and preferably, as the hstspreload site suggests, it should be opt-in.
We noticed this thankfully at our company, and added this command to our /home/dev/startup.sh script:
sed -i '
/Strict-Transport-Security/d
' /etc/nginx/conf.d/spec-settings.conf
- Lenguaje dominante
- HCL
- Estrellas
- 139
- Forks
- 84
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de Azure/wordpress-linux-appservice
-
Dificultad 1/5 1-3 horas Aptitud para principiantes 68/100
Azure/wordpress-linux-appservice#220 · 1 comentario · 1 reacción ·
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
Vulnerable PHP Minor VersionsAbierto
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
Azure/wordpress-linux-appservice#223 · 3 comentarios ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 38/100
-
Dificultad 3/5 1-2 días Aptitud para principiantes 48/100
Todos los issues de Azure/wordpress-linux-appservice
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
area/cli kind/bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 90/100
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
alunduil/zfs-replicate#730 ·
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
infrastructure
Dificultad 1/5 1-3 horas Aptitud para principiantes 65/100
alunduil/siren-json.hs#232 ·
Los mantenedores suelen responder en 1 día