Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
From the [RFC documentation](https://tools.ietf.org/html/rfc6797#section-7.2) it seems like we "SHOULD" make the http->https redirect permanent (301) instead of a temporary redirect (302), and that we "MUST NOT" include an STS header in our redirect response over HTTP which is insecure.
- Loading branch information