Sunday, May 29, 2022

Skip basic authentication headers before passing a request to proxypass target host

This can be done via "RequestHeader unset Authorization" 


<Location "/some_path">

    Require all granted

    ProxyPass https://target-host

    RequestHeader unset Authorization

</Location>


Reference: 1, 2

CSP on Apache

To add CSP to root if sort of funny. The following will NOT work for most cases !!     <LocationMatch "^/$">        Header s...