Re: [whatwg/fetch] Double-keyed HSTS (#920)

We’ve restricted setting HSTS to the first party since 2013 IIRC. But you could set it for any subdomain that matched the registrable domain. That’s what changed more recently, as outlined in the blog post you refer to.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/whatwg/fetch/issues/920#issuecomment-522577863

Received on Monday, 19 August 2019 13:35:08 UTC