Skip to Main Content

APEX

Announcement

For appeals, questions and feedback about Oracle Forums, please email oracle-forums-moderators_us@oracle.com. Technical questions should be asked in the appropriate category. Thank you!

Server 500 error when set Strict-Transport-Security header within APEX

AndyH6 hours ago — edited 5 hours ago

Running APEX 24.2, ORDS in standalone mode, locally hosted database.

We're setting security headers in Browser Security Attributes / HTTP Reponse Headers e.g. Content-Security-Policy.

If we set a Strict-Transport-Security header, the application crashes with an HTTP 500 server error on opening the login page.

The APEX runtime continues to run as expected and with the STS header in the generated output.

Any idea why this would be?

Comments
Post Details
Added 6 hours ago
0 comments
15 views