Skip to content

Strict Transport Security #34

@mvl22

Description

@mvl22

Once full-HTTPS has been in place for a while, we should enable Strict Transport Security, using:

Strict-Transport-Security: max-age=31536000; includeSubDomains;

We should only add this once happy that there are no confirmed situations where mixed content could arise, either existing, or in the future (e.g. embedding third-party images if auto-pull from another site is being done).

So I think this needs to be added cautiously; my experience so far is that you absolutely have to get it right first time, as you can't back out - a browser (as designed) caches the instruction for the given time.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions