SAP Knowledge Base Article - Preview

3332088 - Changing HSTS header using xss filter for storefront not working

Symptom

Changing HSTS header following Injecting Static HTTP Response Headers in Cloud Portal -> Storefront Service using below property doesn't work, e.g. for ootb yacceleratorstorefront.

yacceleratorstorefront.xss.filter.header.Strict-Transport-Security=max-age=0; includeSubDomains

When you check storefront page with browser Developer Tools open, from the Network>Headers>Response Headers of the request url, you can always find "Strict-Transport-Security: max-age=31536000 ; includeSubDomains".

Image/data in this KBA is from SAP internal systems, sample data, or demo systems. Any resemblance to real data is purely coincidental.


Read more...

Environment

SAP Commerce Cloud

Product

SAP Commerce Cloud all versions

Keywords

KBA , CEC-SCC-PLA-PL , Platform , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.