Skip to content

Commit bdb452e

Browse files
authored
Skip localhost when evaluating HSTS upgrades
Fixes #1780.
1 parent 1dc1b03 commit bdb452e

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

fetch.bs

+2
Original file line numberDiff line numberDiff line change
@@ -4509,6 +4509,8 @@ steps:
45094509
"<code>http</code>"
45104510
<li><var>request</var>'s <a for=request>current URL</a>'s <a for=url>host</a> is a
45114511
<a for=/>domain</a>
4512+
<li><var>request</var>'s <a for=request>current URL</a>'s <a for=url>host</a>'s
4513+
<a for=host>public suffix</a> is not "<code>localhost</code>" or "<code>localhost.</code>"
45124514
<li>Matching <var>request</var>'s <a for=request>current URL</a>'s <a for=url>host</a> per
45134515
<a href=https://www.rfc-editor.org/rfc/rfc6797.html#section-8.2>Known HSTS Host Domain Name Matching</a>
45144516
results in either a superdomain match with an asserted <code>includeSubDomains</code> directive

0 commit comments

Comments
 (0)