`Strict-Transport-Security` header detected incorrectly
Big-Cake-jpg opened this issue · 2 comments
Big-Cake-jpg commented
lgarron commented
but
hstspreload.org
said that this domain doesn't have any HSTS header.
Checking the response for https://lihaoyu.cn
in Chrome DevTools and cURL
/HTTPie, that looks correct. The site needs to resume sending the header to stay preloaded.
nharper commented
I concur with @lgarron's assessment. This appears to be a configuration issue with the website, not an issue with hstspreload.org. One possible explanation for why lgarron, hstspreload.org, and I don't see the HSTS header is that it's possible that the website only sends the HSTS header under some conditions.