Skip to content

Comment on HTTPS Watchparent

Comments

It's part of the HSTS spec that a server receiving a request over HTTP should redirect to HTTPS.

I assume the logic here is that as it's best practice for any site with HTTPS to use HSTS also, all HTTPS sites should not be available over HTTP apart from a redirect to the secure version of the page.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.