Cleared 1m ago · benbalter/site-inspector #127 · Ruby · ★ 90 · MIT

`Hsts#valid?` accepts headers with no `max-age`

RFC 6797 §6.1.1 makes max-age a required directive. valid? only checks that the header isn't empty and has no stray quotes or whitespace (lib/site-inspector/endpoint/hsts.rb:10-14), so Strict-Transport-Security: includeSubDomains is reported as valid. Acceptance criteria: valid?…

What we checked

Similar unclaimed issues