General¶
In the console: Settings › Network › HTTP › General
How the web server answers: extra headers, and trusting addresses passed on by a proxy.
Response¶
Headers¶
Additional headers to include in HTTP responses.
A set of entries, each a key and its value. Name in the API: responseHeaders.
Redirect root¶
The URL to redirect users to when they access the root path of the HTTP server. If not set, the server will return a 404 Not Found response.
Text. Default: /account. Name in the API: redirectRoot.
Proxy¶
Obtain remote IP from Forwarded header¶
Specifies whether to use the Forwarded or X-Forwarded-For header to determine the client's IP address.
On or off. Name in the API: useXForwarded.
Other settings¶
Allowed endpoints¶
An expression that determines whether access to an endpoint is allowed. The expression should an HTTP status code (200, 403, etc.)
Settings of their own: see Expression. Name in the API: allowedEndpoints.
Enable hsts¶
Specifies whether to enable HTTP Strict Transport Security for the HTTP server.
On or off. Name in the API: enableHsts.
Rate limit anonymous¶
Specifies the request rate limit for unauthenticated users.
Settings of their own: see Rate. Name in the API: rateLimitAnonymous.
Rate limit authenticated¶
Specifies the request rate limit for authenticated users.
Settings of their own: see Rate. Name in the API: rateLimitAuthenticated.
Use permissive cors¶
Specifies whether to allow all origins in the CORS policy for the HTTP server.
On or off. Name in the API: usePermissiveCors.