diff --git a/swag/nginx/proxy-confs/nitter.subdomain.conf b/swag/nginx/proxy-confs/nitter.subdomain.conf index 1ea9845..179d876 100644 --- a/swag/nginx/proxy-confs/nitter.subdomain.conf +++ b/swag/nginx/proxy-confs/nitter.subdomain.conf @@ -8,6 +8,9 @@ server { include /config/nginx/ssl.conf; + # HSTS (ngx_http_headers_module is required) (63072000 seconds) + add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always; + client_max_body_size 0; location / { diff --git a/swag/nginx/ssl.conf b/swag/nginx/ssl.conf index 0777bd2..eb2b40a 100644 --- a/swag/nginx/ssl.conf +++ b/swag/nginx/ssl.conf @@ -19,9 +19,6 @@ ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDS ssl_prefer_server_ciphers on; ssl_conf_command Options PrioritizeChaCha; -# HSTS (ngx_http_headers_module is required) (63072000 seconds) -add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload" always; - # OCSP stapling ssl_stapling on; ssl_stapling_verify on;