AnsweredAssumed Answered

HSTS in Customize error response

Question asked by Pramod.Talekar on Mar 11, 2019
Latest reply on Mar 11, 2019 by Mark_HE

Hi All, 

 

I am using the Customize error response assertion to pass on the errors to the UI component.

I have added few extra response headers to this assertion.

For error cases, I have added Extra repsonse header for HSTS details as below :

Name : Strict-Transport-Security

value : ${request.http.header.Strict-Transport-Security}

 

This gives empty value to the UI component in case of errors.

 

The HSTS related assertion works fine in case of success scenarios which is added in the Global policy fragment .

As I had already added the HSTS related Strict-Transport-Security header in the Global policy fragment,  was expecting the same to appear in response header for error scenarios but that doesn't seem to be working.

 

Any suggestion please.

 

Regards,

Pramod Talekar

Outcomes