petitssuisses / piwigo-ForceHTTPS

Piwigo Force HTTPS is a security plugin for Piwigo. It allows Piwigo administrators to force usage of SSL transport layer when browsing Piwigo.
4 stars 3 forks source link

Value of 500 too low for STS max age #3

Closed petitssuisses closed 7 years ago

petitssuisses commented 7 years ago

See http://piwigo.org/forum/viewtopic.php?id=22026&p=2 for source and https://wiki.mozilla.org/Security/Guidelines/Web_Security#HTTP_Strict_Transport_Security for reference. To implement option based value and default with at least 6 months