Risks of not enabling HSTS on a static content subdomain. Even though main domain does have hsts
I’m investigating an issue where our static content (js, css) is deployed in AWS Cloudfront under a subdomain of our main website and doesn’t have HSTS enabled. The main domain does have HSTS enabled however.
Presuming our c… Continue reading Risks of not enabling HSTS on a static content subdomain. Even though main domain does have hsts