fix: disable upgrade-insecure-requests for local HTTP access
Helmet's default CSP includes upgrade-insecure-requests, which causes browsers to upgrade all resource requests (CSS, JS, etc.) to HTTPS. This breaks LuHost when accessed over HTTP on the local network. Explicitly disable it so HTTP-only deployments work correctly.
This commit is contained in:
Reference in New Issue
Block a user