18F / 2015-foia-hub

A consolidated FOIA request hub.
48 stars 17 forks source link

Enable HSTS header #658

Closed konklone closed 9 years ago

konklone commented 9 years ago

I realized two things about HTTP Strict Transport Security and this project:

Even if I am somehow wrong about the above, the worst case is that we remove the HSTS header, and the affected development team clears their HSTS cache (in Chrome, this is at chrome://net-internals#hsts). But I'm pretty sure there's no reason to think we'd even have to do that.

Fixes #618.