Remove content security header upgrade-insecure-requests which breaks http only server configs

This commit is contained in:
Eduard Heimbuch
2023-07-27 09:21:03 +02:00
parent 640f136365
commit f6b3d969a1

View File

@@ -44,7 +44,6 @@ public class SecurityHeadersFilter extends HttpFilter {
"form-action 'self'; " +
"object-src 'none'; " +
"frame-ancestors 'none'; " +
"upgrade-insecure-requests; " +
"block-all-mixed-content"
);
response.setHeader("Permissions-Policy",