If a site sends max-age=31536000 and then subsequently sends max-age=3, does the second header overwrite the first? If so, then you can in fact go back as long as you're willing to continue supporting HTTPS until the longest max-age header you ever sent has expired.
Comments
If a site sends max-age=31536000 and then subsequently sends max-age=3, does the second header overwrite the first? If so, then you can in fact go back as long as you're willing to continue supporting HTTPS until the longest max-age header you ever sent has expired.