Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Change the "multiple HSTS headers" error into a warning? #99

Open
lgarron opened this issue Mar 7, 2017 · 0 comments
Open

Change the "multiple HSTS headers" error into a warning? #99

lgarron opened this issue Mar 7, 2017 · 0 comments

Comments

@lgarron
Copy link
Collaborator

lgarron commented Mar 7, 2017

RFC6769, section 8.1:

If a UA receives more than one STS header field in an HTTP response message over secure transport, then the UA MUST process only the first such header field.

I think it's better to be strict here (even if the spec is clear, multiple headers can be confusing to debug), but a warning might be sufficient.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant