• Resolved boxhamster

    (@boxhamster)


    Hi,
    I’ve noticed this issue on two of my websites now.
    I use “Simple CAPTCHA Alternative with Cloudflare Turnstile” to add turnstyle on my login pages/forms. When HSTS is activated, the turnstyle does not show. Only when deactivating the plugin (via FTP) I can login, then reactivate the plugin. In other CSP plugins one can add domains to the allow list, but I don’t see how I could do that with HSTS.

    Can you suggest a workaround here or can I provide any further information? Thank you.

    The page I need help with: [log in to see the link]

Viewing 4 replies - 1 through 4 (of 4 total)
  • Thread Starter boxhamster

    (@boxhamster)

    I’ve found this thread since: https://wordpress.org/support/topic/script-src-object-src/
    I’ve got pretty much everything working now, just a bunch of “Report-Only policy” console logs. Can I ignore these?

    Plugin Author Andrea Ferro

    (@unicorn03)

    hi @boxhamster,

    Grazie per aver aperto questo topic. Sono Andrea e ti aiuterò nella tua richiesta.

    To customize the CSP headers / rules you can do it directly in the settings > Headers Security Advanced & HSTS WP.

    The alerts are not serious, I usually configure if I need the CSPs and then I don’t worry about the alerts.

    Once you have obtained the CSP rules from one of the tools, follow these steps to add them using the “Headers Security Advanced & HSTS WP” plugin:

    1. Access the Plugin Settings:
    • In your WordPress website, log in to the administration area and navigate to the installed plugins section.
    • Find and click on the “Headers Security Advanced & HSTS WP”plugin to access its settings.
    • Configure the CSP Header:
    • Inside the plugin settings, look for the “CSP Header” option and click on it to open the CSP rules configuration section.
    • Paste the CSP Rules:
    • In the CSP Header section, you’ll find a field where you can paste the CSP rules generated previously by the tool.
    • Paste the rules into the designated field, ensuring they are correctly formatted.
    • Save the Changes:
    • After pasting the CSP rules, click on “Save” or “Update” to apply the changes.

    The topic you found is very detailed where I explained everything but if you have any problems or want more information you can also use support@openheaders.org

    Thread Starter boxhamster

    (@boxhamster)

    Thank you. As I had mentioned, I had found the instructions above and was able to add the CSP rules. Nota bene, I was not aware that one had to do this and had the plugin running for a year at least. Maybe the onboarding could be enhanced somehow?

    Apart from that, the only issue I have now is that Elementor does not load (the editor) with HSTS activated. Is this a known issue or something I can configure to work?

    Thank you 🙂

    Plugin Author Andrea Ferro

    (@unicorn03)

    Hi @boxhamster,

    Thanks for your reply. I saw you’d found the solution in a previous thread where I’d replied. I’ve reposted the solution since this thread is more recent.

    Regarding your note about onboarding: thank you, that’s very valuable feedback 🙏
    I’m currently improving the plugin’s documentation and interface to better explain this and guide users when enabling more stringent and custom rules.

    If you write to me at support@openheaders.org I can help you verify the problem as quickly as possible.

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Cannot login with HSTS activated as Turnstyle is not showing’ is closed to new replies.