HTTP Strict Transport Security for a Pyramid application.
Project description
Enforce [HTTP Strict Transport Security][] for a [Pyramid][] web application.
### Features
adds a Strict-Transport-Security header to every response
redirects requests with an insecure protocol to the corresponding secure protocol, i.e.: from http://… to https://…
ensures urls generated by request.*_url methods (e.g.: request.route_url) use a secure protocol
### Usage
To use, pip install pyramid_hsts / add pyramid_hsts to your requirements.txt and then [include][] the package:
config.include(‘pyramid_hsts’)
### Configuration
If you’re running behind a frontend that proxies secure requests to your app on an insecure protocol (e.g.: on Heroku or a common Nginx setup) then it is common practice for the frontend to set a header indicating the original prototcol. To read this, you need to [specify][] the name of the protocol_header:
# must be specified if behind proxy hsts.protocol_header=X-Forwarded-Proto
You can also specify the max_age of and whether to include_subdomains in your HSTS header, e.g.:
# defaults to 10886400 hsts.max_age=21772800
# both default to true hsts.include_subdomains=false hsts.preload=false
[HTTP Strict Transport Security]: http://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [Pyramid]: http://pypi.python.org/pypi/pyramid [include]: http://docs.pylonsproject.org/projects/pyramid/en/latest/api/config.html#pyramid.config.Configurator.include [specify]: http://docs.pylonsproject.org/projects/pyramid/en/latest/narr/environment.html#adding-a-custom-setting
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
File details
Details for the file pyramid_hsts-1.2.1.tar.gz
.
File metadata
- Download URL: pyramid_hsts-1.2.1.tar.gz
- Upload date:
- Size: 5.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 4c2c8885a91e9f91113cef028f2f0a55c62a6bbfd1f3341e9e33b70371cd70fe |
|
MD5 | cd673b7994981c81aa372a8ca8d697cf |
|
BLAKE2b-256 | c9a1f93dedef6092d3789f4c826d9db9f367df54e1e7bbba02ce27eaff448c62 |