From be194c5b5bef563ea38e85f784e6e9a3e8f181e1 Mon Sep 17 00:00:00 2001 From: Lukas Reschke Date: Thu, 14 Feb 2013 19:23:29 +0100 Subject: [PATCH] Invalidate existing HSTS headers --- lib/base.php | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/lib/base.php b/lib/base.php index fd9a1d41121..ff95a87e438 100644 --- a/lib/base.php +++ b/lib/base.php @@ -231,6 +231,11 @@ class OC { header("Location: $url"); exit(); } + } else { + // Invalidate HSTS headers + if (OC_Request::serverProtocol() === 'https') { + header('Strict-Transport-Security: max-age=0'); + } } } -- 2.39.5