HSTS not being set

Viewed 727

I am trying to set an Http Strict-Transport-Security header using Asp.Net Core 3. I got it to work perfectly fine in a development environment, whoever when publishing to Heroku (using https://elements.heroku.com/buildpacks/jincod/dotnetcore-buildpack) the header never shows up (on any page, over http and https).

            if (env.IsDevelopment()) {
                app.UseDeveloperExceptionPage();
                app.UseDatabaseErrorPage();
                app.UseBrowserLink();
                app.UseHsts(hsts => hsts.IncludeSubdomains().MaxAge(hours: 1));
            } else {
                app.UseExceptionHandler("/About/Error");
                // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
                app.UseHsts(hsts => hsts.IncludeSubdomains().MaxAge(days: 366));
            }

Any help is greatly appreciated!

What I tried

I tried using the built in UseHSTS method in Configure and adding AddHSTS to ConfigureServices. Than I tried using the NWebsec package's UseHSTS (in Configure) with the the same options with no success.

1 Answers

Here example configuration for https https://github.com/jincod/AspNetCoreDemoApp/blob/master/src/AspNetCoreDemoApp/Startup.cs

ConfigureServices:

services.AddHttpsRedirection(options => { options.HttpsPort = 443; })
...
services.Configure<ForwardedHeadersOptions>(options =>
{
    options.ForwardedHeaders = ForwardedHeaders.XForwardedFor |
                                ForwardedHeaders.XForwardedProto;
    options.KnownNetworks.Clear();
    options.KnownProxies.Clear();
});

Configure:

app.UseForwardedHeaders();
...
app.UseHttpsRedirection();

More info https://devcenter.heroku.com/articles/http-routing#routing and https://github.com/aspnet/Announcements/issues/301

Related