mendix / docs

Mendix documentation repository
https://docs.mendix.com
Creative Commons Attribution 4.0 International
139 stars 716 forks source link

Windows deployment guide missing important security setting #110

Closed tieniber closed 5 years ago

tieniber commented 7 years ago

Per this discussion on the forums, I think the rewrite rules section in Deploying Mendix on Microsoft WIndows needs to be updated to include setting a server variable / http header that is recommended in Security Checklist for your On-Premises Installation.

I'm still awaiting a positive response on the forum but wanted to note it here before I forget.

Adam-Dupaski commented 7 years ago

Hi Eric, after you get verification from Paul on your forum answer, please update the documentation with what's necessary and send a pull request for us to review. This should be done for the how-to in versions 5-7 if relevant. Thanks.

tieniber commented 7 years ago

Ok, this answer was confirmed working. It apparently requires setting up a URL rewrite rule at the server level rather than at the site level. I don't have an instance of IIS to step through the process and take good screenshots. I may have one available to me in 2-3 weeks.

Adam-Dupaski commented 7 years ago

Thanks for the update, Eric. Please keep me posted about updating the documentation when you have an environment available.

jandevriesmendix commented 7 years ago

Any updates on this?

Adam-Dupaski commented 5 years ago

Hi, I believe this has been taken care of here: https://docs.mendix.com/developerportal/deploy/deploy-mendix-on-microsoft-windows#5-4-2-rule-add-x-forwarded-proto-header @tieniber please let me know if there's something missing