3 Jan 2012 00:29
default value for max-age ? (was: Re: Strict-Transport-Security syntax redux)
=JeffH <Jeff.Hodges <at> KingsMountain.com>
2012-01-02 23:29:20 GMT
2012-01-02 23:29:20 GMT
Julian wondered.. > > wouldn't it make sense to have a default for max-age so it > can be made OPTIONAL? hm ... I lean towards keeping max-age as REQUIRED (without a default value) and thus hopefully encouraging deployers to think a bit about this and its ramifications, and also because its value is so site-specific in terms of a web application's needs, deployment approach, and tolerance for downside risk of breaking itself. =JeffH
RSS Feed