Must enforce SSL for customer status page #390

Closed
opened 2026-04-05 16:19:32 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @cjanz4711 on 9/5/2025

Customer status pages with vanity URL's and certificates applied have no option to enforce SSL.

This is causing many problems for us and has been raised as an audit finding. We cannot allow http traffic for pages that have customer data. We require SSL enforcement and must be able to disallow http port 80 traffic in all instances where customer data is stored, which includes customer status pages hosted by OneUptime. Please consider this with urgency.

*Originally created by @cjanz4711 on 9/5/2025* Customer status pages with vanity URL's and certificates applied have no option to enforce SSL. This is causing many problems for us and has been raised as an audit finding. We cannot allow http traffic for pages that have customer data. We require SSL enforcement and must be able to disallow http port 80 traffic in all instances where customer data is stored, which includes customer status pages hosted by OneUptime. Please consider this with urgency.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/oneuptime#390