Comments (3)
I'll casually experiment why https://github.com/zowe/sample-spring-boot-api-service/blob/master/zowe-rest-api-sample-spring/src/main/java/org/zowe/sample/apiservice/config/WebSecurityConfig.java#L34
doesn't seem to take effect here.
from sample-spring-boot-api-service.
The sample application should not set HSTS headers. If it does then it is a bug. I do not think that the sample does that. It can be set by another app running on the same host because this setting applies to the host and the port is ignored.
There are two options as a workaround:
- Remove the setting using the procedure in https://www.ssl2buy.com/wiki/how-to-clear-hsts-settings-on-chrome-firefox-and-ie-browsers
- Open a new incognito window in your browser
It would be good to find out what service sets it because. HSTS is a useful mechanism on production servers since it enforces HTTPS to be required by modern browsers. But it can be limiting on development systems since it forbids self-signed certificates and HTTP connections which can be useful during development.
from sample-spring-boot-api-service.
Hi Petr,
Option 2 worked for me, but I don't really understand why. I'll close this in the meantime and later adjust my Chrome config.
Thank you,
Dan
from sample-spring-boot-api-service.
Related Issues (20)
- "https" profile in application.yml has no effect
- Misleading security message in rest-api-commons
- Proxy problem HOT 1
- Document Manual Deployment
- Document zowe-api.json
- zowe-api-dev init generates incorrect zosTargetDir HOT 1
- zowe-api-dev start --job not documented
- zowe-api-dev stop supports only java started by Jzos launcher HOT 3
- zowe-api-dev Variable replacing HOT 1
- zowe-api-dev config --force HOT 1
- Problems registering Zowe Sample API Service HOT 5
- OMVS Segment Required
- Were MFAAS dependencies moved to https://zowe.jfrog.io/? HOT 2
- zowe-api-dev config --name zos Cannot use template
- Use zowe.jfrog.io
- Minor defect - Missing period in error message
- List used third-party components so the SDK can be easily approved
- Document methods for taking diagnostics information
- Security Documentation - Commands and Requirements Don't Match HOT 3
- Make SonarCloud work for pull requests with CircleCI
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from sample-spring-boot-api-service.