Uploaded image for project: 'Red Hat OpenStack Services on OpenShift'
  1. Red Hat OpenStack Services on OpenShift
  2. OSPRH-5946

Ensure all the headers are configured in Horizon for https

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • rhos-18.0.0
    • None
    • horizon-operator
    • None
    • 3

      We need to enable secure cookies, HSTS, etc. as it was enabled with tripleo.

      In the previous release, the relevant code looked like this: https://github.com/openstack/puppet-horizon/blob/master/templates/local_settings.py.erb#L27-L54

      We need similar settings with the horizon-operator.

      The bugs related to HSTS in the previous release:

      We will need to add something similar to the horizon-operator.

      Django documentation: https://docs.djangoproject.com/en/3.2/topics/security/#ssl-https

      Acceptance criteria:

      • horizon response headers contain the required hsts headers
      • the cookies are set as secure

            rhn-engineering-rdopiera Radomir Dopieralski
            rhn-engineering-rdopiera Radomir Dopieralski
            rhos-dfg-ui
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: