From 40b6b06f577299ab6fe82f3a21618d66ba13c657 Mon Sep 17 00:00:00 2001 From: BoHong Li Date: Mon, 2 Mar 2020 11:51:04 +0800 Subject: [PATCH] feat(hsts): trun includeSubdomain to false BREAKING CHANGE: change default setting from `true` to `false` Signed-off-by: BoHong Li --- lib/config/default.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/config/default.js b/lib/config/default.js index b4b7e846..7c5e9b33 100644 --- a/lib/config/default.js +++ b/lib/config/default.js @@ -14,7 +14,7 @@ module.exports = { hsts: { enable: true, maxAgeSeconds: 60 * 60 * 24 * 365, - includeSubdomains: true, + includeSubdomains: false, preload: true }, csp: {