Closed bandrzej closed 6 years ago
Submitted edit prevents HSTS being directly applied in HTTP headers against HSTS specification section 7.12:
An HSTS Host MUST NOT include the STS header field in HTTP responses conveyed over non-secure transport.
SOURCE: https://tools.ietf.org/html/rfc6797#section-7.2
@bandrzej Thanks! (And sorry for the delay, I somehow missed the notification of this issue.)
I don't have a way of testing this myself, but I'm happy to trust your work here. Thanks for the improvement!
Submitted edit prevents HSTS being directly applied in HTTP headers against HSTS specification section 7.12:
SOURCE:
https://tools.ietf.org/html/rfc6797#section-7.2