dddeastanglia / DDDEastAnglia

DDD East Anglia website
https://www.dddeastanglia.com
7 stars 10 forks source link

Only send the STS header over https #374

Closed philpursglove closed 2 years ago

philpursglove commented 6 years ago

To be technically correct, the Strict Transport Security header should only be sent over https. Sending it over http doesn't affect our rating on SecurityHeaders.com, but we want to follow the spec...