Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Don't set the Strict-Transport-Security header, which causes browsers to make all further connections to the same host by HTTPS even when the user requests HTTP, when accessed as "localhost", because that breaks all other non-HTTPS services a user may have running on their machine, and the saved setting is a pain to get out of the system especially with Safari, where it also affects other applications that use the OS HTTP APIs (here's how: https://apple.stackexchange.com/questions/227662/how-do-i-fully-flush-cached-redirects-from-safari/285468#288002).
- Loading branch information