mirror of
https://github.com/mattermost/mattermost.git
synced 2026-08-30 17:06:34 +08:00
245e311a41
* [MM-57807] Graduate Hardened Mode to Environment > Web Server
Hardened Mode is a production security control, but it was only reachable
from System Console > Experimental > Features, which led admins to doubt
it was supported for production use.
Move Hardened Mode to Environment > Web Server, where the other
server-side transport and API hardening toggles already live, and
reclassify its access tag from experimental_features to
environment_web_server so it is gated by
sysconsole_{read,write}_environment_web_server.
The config key is renamed from ExperimentalEnableHardenedMode to
EnableHardenedMode. On first load after upgrade, SetDefaults migrates any
existing ExperimentalEnableHardenedMode: true to the new key and clears
the old one, so no manual config change is required.
* Fix hyphen in hardened mode docs (user-facing)
* Initialize ExperimentalEnableHardenedMode to false when nil
Symmetric with other *bool settings in SetDefaults. The deprecated field
is now always non-nil after initialization; its value still seeds
EnableHardenedMode when that field is unset.
* fixup! Initialize ExperimentalEnableHardenedMode to false when nil
---------
Co-authored-by: Mattermost Build <build@mattermost.com>