From e35748567c431c3a092816bfbab0d2f5043284b1 Mon Sep 17 00:00:00 2001 From: Tom Hughes Date: Fri, 3 Mar 2017 11:34:39 +0000 Subject: [PATCH] Update HSTS to publish a max-age=0 to disable it --- config/initializers/secure_headers.rb | 1 + 1 file changed, 1 insertion(+) diff --git a/config/initializers/secure_headers.rb b/config/initializers/secure_headers.rb index d1863fdd2..e53ea6cef 100644 --- a/config/initializers/secure_headers.rb +++ b/config/initializers/secure_headers.rb @@ -21,6 +21,7 @@ else end SecureHeaders::Configuration.default do |config| + config.hsts = "max-age=0" config.csp = SecureHeaders::OPT_OUT config.csp_report_only = policy end -- 2.43.2