Closed lgarron closed 5 months ago
I'd send a pull request, but this codebase only seems to serve the response for "https://www.gitpod.io"
.
Hi @lgarron ! Thanks for raising this and offering to help ✨
but this codebase only seems to serve the response for "https://www.gitpod.io".
https://gitpod.io would be based on https://github.com/gitpod-io/gitpod AFAIK.
https://gitpod.io would be based on https://github.com/gitpod-io/gitpod AFAIK.
Thanks! Any chance I could ask you to move the issue there?
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
Description
I see that
www.gitpod.io
is serving:However,
gitpod.io
is serving:It would be great to send the same header for
gitpod.io
, so that allgitpod.io
subdomains can be protected from HTTP tampering and HTTPS downgrade attacks through HSTS preloading: https://hstspreload.org/?domain=gitpod.io