Skip to content

HSTS invalid max-age validation #492

@kshitijshresth

Description

@kshitijshresth

parse_hsts_header("max-age=meow") currently parses as max_age = 0. RFC 6797 defines max-age as numeric delta-seconds. Would a PR rejecting non-numeric values with a unit test be acceptable?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions