Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions src/main/java/io/openliberty/website/SecurityFilter.java
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,9 @@ public void doFilter(ServletRequest req, ServletResponse resp, FilterChain chain
} else if ("https".equals(req.getScheme())) {
// If HTTPS is configured this sets a bunch of security headers

// Remove X-Powered-By header to prevent information disclosure (OWASP recommendation)
response.setHeader("X-Powered-By", "");

// Tell browsers that this site should only be accessed using HTTPS, instead of using HTTP.
// IncludeSubDomains and 1 year set per OWASP.
response.setHeader("Strict-Transport-Security", "max-age=31536000; includeSubDomains");
Expand Down