Opened 4 years ago

Closed 9 months ago

#17103 closed New feature (fixed)

Add HTTP Strict Transport Security support, to improve support for all-SSL sites

Reported by: carljm Owned by: nobody
Component: HTTP handling Version: master
Severity: Normal Keywords:
Cc: zborboa@… Triage Stage: Accepted
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no

Description

Since you pretty much shouldn't do anything with sessions or logins on a public site without SSL, I think a solid majority of public Django sites probably ought to be all-SSL. Given this, I think Django core should provide good support for all-SSL sites out of the box.

HSTS (HTTP Strict Transport Security) is an HTTP response header that allows a site to tell a browser to only ever access it over HTTPS. This avoids the need for redirect-to-SSL on repeat visits and reduces exposure to various types of attacks.

There is an existing implementation of HSTS in django-secure.

Change History (4)

comment:1 Changed 4 years ago by aaugustin

  • Triage Stage changed from Unreviewed to Accepted

comment:2 Changed 19 months ago by zborboa@…

  • Cc zborboa@… added

comment:3 Changed 9 months ago by erikr

This was fixed in 52ef6a47269a455113d95992f868939131f9c10c as part of #17101.

comment:4 Changed 9 months ago by erikr

  • Resolution set to fixed
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.
Back to Top