When an HTTPS response carries a Strict-Transport-Security header, the received policy is now respected. Subsequent HTTP requests to a known HSTS host are upgraded to HTTPS before the fetch algorithm makes further decisions such as CORS and mixed content. Fixes tpexpress.co.uk, where an XHR redirects HTTPS -> HTTP -> HTTPS, relying on a HSTS policy received on the document response to avoid the CORS failure. |
||
|---|---|---|
| .. | ||
| CMakeLists.txt | ||
| TestCacheIndex.cpp | ||
| TestCacheUtilities.cpp | ||
| TestDiskCache.cpp | ||
| TestHSTSPolicy.cpp | ||
| TestHTTPUtils.cpp | ||