risdenk commented on PR #332:
URL: https://github.com/apache/solr/pull/332#issuecomment-1279835012

   So we should be careful about just adding this. The HSTS header affects the 
browser and all host/subdomains. Its really ugly when "includeSubDomains" 
forces all things under `company.com` or whatever to require HTTPS. I'd prefer 
it be something that can be opted into separate and not just something that is 
forced if there is HTTPS enabled.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to