Closed jmanico closed 3 years ago
From requirement I don't read that there should be max-age at least one year, I read it as syntax example.
If you want to have preload, then you may consider https://hstspreload.org/
Yes I want to increase that syntax example since folks copy it and I opened a PR.
Added the modified tag :)
Do you want to mention preload somewhere?
CWE-523 does not seem perfect match. If you make those changes already :)
Maybe as a ASVS 3 new item
I moved this to https://github.com/OWASP/ASVS/issues/966 and am closing this up
And good call on this one @tghosth thank you!
This seems pretty weak, lets bump this to a full year so preloading is possible