Yes, there’s the issue of scope mismatch, the HSTS bootstrap request, older browsers, and misconfiguration. Seems prudent to still set Secure.
Mar 28, 2019 · 12:10 AM UTC
1
1
Mar 28, 2019 · 12:10 AM UTC