From: Tom Hughes Date: Fri, 3 Mar 2017 11:34:39 +0000 (+0000) Subject: Update HSTS to publish a max-age=0 to disable it X-Git-Tag: live~3566 X-Git-Url: https://git.openstreetmap.org/rails.git/commitdiff_plain/e35748567c431c3a092816bfbab0d2f5043284b1 Update HSTS to publish a max-age=0 to disable it --- diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index d1863fdd2..e53ea6cef 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -21,6 +21,7 @@ else end SecureHeaders::Configuration.default do |config| + config.hsts = "max-age=0" config.csp = SecureHeaders::OPT_OUT config.csp_report_only = policy end