HSTS support.

1,579 views
Skip to first unread message

Roney Thomas

unread,
Sep 22, 2016, 7:25:30 AM9/22/16
to Firebase Google Group
I am extremely pleased with using firebase hosting. This is really amazing. Thanks for add http2.
One thing i would really love is HSTS preloading support.
I tried to set HSTS headers and got a error saying "HTTP Error: 400, hosting.headers[1].headers[0].key is not one of enum values: Cache-Control,Access-Control-Allow-Origin,X-UA-Compatible,X-Content-Type-Options,X-Frame-Options,X-XSS-Protection,Content-Type,Link,Content-Security-Policy"

From the error it seems firebase hosting doesn't support "strict-transport-security" header.

Michael Bleigh

unread,
Sep 22, 2016, 1:26:54 PM9/22/16
to fireba...@googlegroups.com
Hi Roney,

Firebase Hosting automatically adds HSTS headers to all hosted sites, but we currently don't support the preload option. This is something that we can consider making configurable in the future if we see enough customer demand.

Cheers,
Michael

--
You received this message because you are subscribed to the Google Groups "Firebase Google Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to firebase-tal...@googlegroups.com.
To post to this group, send email to fireba...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/firebase-talk/425cb048-5a68-4ab5-b151-50b4464f37ea%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Maximillian Laumeister

unread,
Feb 19, 2017, 4:54:59 PM2/19/17
to Firebase Google Group
Hi Michael,

Where should customers go to register their interest in HSTS preload support? Or is posting in this topic enough?

Thanks!
-Max

Anders Sandvik

unread,
Mar 2, 2017, 10:28:32 AM3/2/17
to Firebase Google Group
Where should customers go to register their interest in HSTS preload support?

Michael Bleigh

unread,
Mar 2, 2017, 10:53:38 AM3/2/17
to Firebase Google Group

Shifaat Iqbal

unread,
Apr 25, 2017, 9:35:02 AM4/25/17
to Firebase Google Group
Hi Michael,

Any updates on this?

Michael Bleigh

unread,
Apr 25, 2017, 1:43:37 PM4/25/17
to Firebase Google Group
No update as yet. Your interest is registered, though!

Abraham Williams

unread,
Aug 22, 2017, 11:19:47 AM8/22/17
to Firebase Google Group
HSTS Preloading is a feature that I'm also interested in.

- Abraham

Reinaert Van de Cruys

unread,
Dec 3, 2017, 12:37:01 PM12/3/17
to Firebase Google Group
I'm also interested in having an HSTS preload option.

M

unread,
Dec 4, 2017, 10:02:14 AM12/4/17
to Firebase Google Group
I'd argue that everyone using Firebase Hosting should enable preloading. The only reason you'd want not to do it is if you later on decided to no longer use Firebase Hosting and wanted to serve insecure connections.

So yeah, +1 for the option.

David Murdoch

unread,
Jan 19, 2018, 10:38:02 AM1/19/18
to Firebase Google Group
also interested!

Rory

unread,
Feb 15, 2018, 6:17:18 AM2/15/18
to Firebase Google Group
I'm interested

Steve Simpson

unread,
Feb 26, 2018, 9:11:14 PM2/26/18
to Firebase Google Group
I'm also interested in HSTS preload support :-)
Message has been deleted

Derek Held

unread,
Apr 7, 2018, 12:28:46 AM4/7/18
to Firebase Google Group
I too would like to see HSTS preloading supported.

Natan Sągol

unread,
Jun 24, 2018, 8:13:35 AM6/24/18
to Firebase Google Group
Hello, is this feature anywhere on the roadmap?

Alexis Vapillon

unread,
Sep 7, 2018, 10:11:16 AM9/7/18
to Firebase Google Group
I'm also interested

This email and any files transmitted with it are confidential and are intended solely for the use of the individual or entity to which they are addressed. Access to this e-mail by anyone else is unauthorised. If you are not the intended recipient, any disclosure, copying, distribution or any action taken or omitted to be taken in reliance on it, is prohibited. E-mail messages are not necessarily secure. Archos does not accept responsibility for any changes made to this message after it was sent.

Pierre De Wilde

unread,
Dec 22, 2019, 8:54:06 PM12/22/19
to Firebase Google Group
It would be great to preload our Firebase Hosting apps in HSTS preload list.

Michael Bleigh

unread,
Jan 9, 2020, 5:55:42 PM1/9/20
to Firebase Google Group
Hi Pierre,

Websites are added to HSTS preload on an individual basis. There's nothing stopping you from supplying custom HSTS headers in your firebase.json config and adding your site's custom domain. Is there a specific problem you've run into trying to do so?

-Michael

On Sun, Dec 22, 2019 at 5:54 PM Pierre De Wilde <pierre...@gmail.com> wrote:
It would be great to preload our Firebase Hosting apps in HSTS preload list.

--
You received this message because you are subscribed to the Google Groups "Firebase Google Group" group.
To unsubscribe from this group and stop receiving emails from it, send an email to firebase-tal...@googlegroups.com.

Abraham Williams

unread,
Jan 16, 2020, 10:16:21 AM1/16/20
to fireba...@googlegroups.com
According to https://firebase.google.com/docs/hosting/full-config developers can not set a custom HSTS header.

> Important: Firebase Hosting overwrites the Strict-Transport-Security configuration


You received this message because you are subscribed to a topic in the Google Groups "Firebase Google Group" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/firebase-talk/S6XDEV6TVhk/unsubscribe.
To unsubscribe from this group and all its topics, send an email to firebase-tal...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/firebase-talk/CANPY8KUw5%2BnDAJqGV7v6HGaduHxDrAfW1C1a9-hTAHa12CvSZA%40mail.gmail.com.

Michael Bleigh

unread,
Jan 16, 2020, 10:44:56 AM1/16/20
to Firebase Google Group
Only on the firebaseapp.com and web.app domains iirc. On a custom domain you can specify it. We may need to update docs 🙂

Abraham Williams

unread,
Jan 19, 2020, 11:56:37 AM1/19/20
to fireba...@googlegroups.com
Nice! My defined CSP is applying to my custom domains.
Reply all
Reply to author
Forward
0 new messages