Browse Source

fix: set securityTrustProxy to false by default

Nicolas Giard 1 year ago
parent
commit
b1e1759f25
2 changed files with 2 additions and 2 deletions
  1. 1 1
      client/components/admin/admin-security.vue
  2. 1 1
      server/app/data.yml

+ 1 - 1
client/components/admin/admin-security.vue

@@ -265,7 +265,7 @@ export default {
         securityOpenRedirect: true,
         securityIframe: true,
         securityReferrerPolicy: true,
-        securityTrustProxy: true,
+        securityTrustProxy: false,
         securitySRI: true,
         securityHSTS: false,
         securityHSTSDuration: 0,

+ 1 - 1
server/app/data.yml

@@ -85,7 +85,7 @@ defaults:
       securityOpenRedirect: true
       securityIframe: true
       securityReferrerPolicy: true
-      securityTrustProxy: true
+      securityTrustProxy: false
       securitySRI: true
       securityHSTS: false
       securityHSTSDuration: 300