bcgov / moh-phlat

Repository for the PHLAT registries data loading application
Apache License 2.0
2 stars 0 forks source link

Added HTTP Strict Transport Security(HSTS) Header #87

Closed Ashwani-cgi closed 4 months ago

Ashwani-cgi commented 4 months ago

This PR implements the changes to return HSTS header from cloud front. It was reported as security violation.

It is tested on chrome and Edge latest version available at the time of testing.

Jira Issue: https://proactionca.ent.cgi.com/jira/browse/BCMOHAD-23702

HSTS header returned by Cloud front in test environment on Edge browser

image

HSTS header returned by Cloud front in test environment on Chrome

image