3 ms·
As a side note the thing I find most puzzling about RFC 6797 is that the 'max-age' field can be set to 0 to invalidate the HSTS flag for the domain, but can't b
by ary 14y ago
As a side note the thing I find most puzzling about RFC 6797 is that the 'max-age' field can be set to 0 to invalidate the HSTS flag for the domain, but can't be set to an indefinite value. The inability to deal with stripping before reception of the 'Strict-Transport-Security' header is understandable, but lack of indefinite retention of the HSTS flag is hard to comprehend.
- bluetooth 14y agoSome of the new HTTP headers are just a mess. Did you know that X-Frame-Options' Allow-From option only allows you to whitelist one URL? Not a domain - a URL. The RFC actually expects you to communicate via another channel to determine whether or not a URL will be allowed to frame your page. Luckily, this one is still a draft...
- homakov 14y agoyes lol. design pisses me off. Why didn't they put XFO into Content security policy yet!
- Dylan16807 14y agoWell if you assume that referer is turned on...