The "Strict-Transport-Security" HTTP header is not configured to at least "15552000" seconds.

When running owncloud/server:10.15 in the docker compose container as described in the docs here, a warning is shown under Admin / General / Security & setup warnings.
The "Strict-Transport-Security" HTTP header is not configured to at least "15552000" seconds. For enhanced security we recommend enabling HSTS as described in our security tips. Please double check the installation guides, and check for any errors or warnings in the log.

I wanted to make a bug report about this topic, but the github page mentioned to post it here first. In my opinion, this is a misconfiguration in the owncloud docker image.

Hey,

i’m not sure but i think it could be possible that not enabling this headers by default could be by design. I think i have read somewhere if you have no “correct” / valid certificate setup and if you enable this header you would get blocked out of the system.