aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/server.go
diff options
context:
space:
mode:
Diffstat (limited to 'internal/web/server.go')
-rw-r--r--internal/web/server.go7
1 files changed, 5 insertions, 2 deletions
diff --git a/internal/web/server.go b/internal/web/server.go
index 12440de..f768ebd 100644
--- a/internal/web/server.go
+++ b/internal/web/server.go
@@ -43,6 +43,9 @@ func NewServer(cfg *config.Config, st *store.Store) *Server {
// site plus the superadmin's root blog, one label below it is a blog, anything
// else is a 404.
func (s *Server) ServeHTTP(w http.ResponseWriter, r *http.Request) {
+ if s.cfg.HTTPS { // every subdomain is ours, so the whole site may pin https
+ w.Header().Set("Strict-Transport-Security", "max-age=31536000; includeSubDomains")
+ }
host := hostname(r.Host)
switch {
case host == s.cfg.BaseDomain, host == config.RootSubdomain+"."+s.cfg.BaseDomain:
@@ -178,13 +181,13 @@ func (s *Server) session(next http.Handler) http.Handler {
}
claims, err := auth.ParseToken(s.cfg.JWTSecret, c.Value)
if err != nil {
- auth.ClearSessionCookie(w)
+ auth.ClearSessionCookie(w, s.cfg.HTTPS)
next.ServeHTTP(w, r)
return
}
u, err := s.st.UserByID(r.Context(), claims.UserID)
if err != nil || u.Disabled || u.TokenVersion != claims.TokenVersion {
- auth.ClearSessionCookie(w)
+ auth.ClearSessionCookie(w, s.cfg.HTTPS)
next.ServeHTTP(w, r)
return
}