Possibly related to the new verified-users, unverified-users groups. If your forum had the require email confirmation setting on and you upgraded then registered-users no longer have posting privileges. This is done by the upgrade scripts. But if you reverted without doing a database restore then registered-users won't have the privileges back.
v1.13.1 forcing HSTS (Strict-Transport-Security: max-age=15552000; includeSubDomains)
Cannot avoid HSTS header even if "Strict Transport Security" disabled
$ curl -I http://localhost:4567/bb HTTP/1.1 200 OK X-DNS-Prefetch-Control: off X-Frame-Options: SAMEORIGIN Strict-Transport-Security: max-age=15552000; includeSubDomains X-Download-Options: noopen X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Referrer-Policy: strict-origin-when-cross-origin X-Powered-By: NodeBB set-cookie: _csrf=pKgoXIjK_9iHKUbVENcTWsLD; Path=/; HttpOnly; Secure; SameSite=Strict Content-Type: text/html; charset=utf-8 Content-Length: 33997 ETag: W/"84cd-69RT9fU0GKhJKDANsNxdPOrjvls" Vary: Accept-Encoding Date: Wed, 15 Jan 2020 18:57:13 GMT Connection: keep-alive
Did you restart nodebb after changing the setting?
yes. I did restart.
I would guess that happens because of
var helmet = require('helmet');
var DEFAULT_MIDDLEWARE = [ 'dnsPrefetchControl', 'frameguard', 'hidePoweredBy', 'hsts', // <<<<<<<<<<<<<<<<<< 'ieNoOpen', 'noSniff', 'xssFilter' ]
Yes. It is working now.