Re: Redirects and HSTS

On Sat, Sep 27, 2014 at 2:38 AM, Daniel Veditz <dveditz@mozilla.com> wrote:
> Is it a "stance" or just how the code happened to work? The policy
> enforcement mechanism for content loading is undergoing changes in Gecko
> and unless this was a conscious design it might just start working the
> other way.

There's https://bugzilla.mozilla.org/show_bug.cgi?id=838395#c5 on
file. https://fetch.spec.whatwg.org/ currently requires HSTS before
Mixed Content, but we could flip it around.


-- 
https://annevankesteren.nl/

Received on Saturday, 27 September 2014 06:38:15 UTC