From be194c5b5bef563ea38e85f784e6e9a3e8f181e1 Mon Sep 17 00:00:00 2001
From: Lukas Reschke <lukas@statuscode.ch>
Date: Thu, 14 Feb 2013 19:23:29 +0100
Subject: [PATCH] Invalidate existing HSTS headers

---
 lib/base.php | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/lib/base.php b/lib/base.php
index fd9a1d4112..ff95a87e43 100644
--- a/lib/base.php
+++ b/lib/base.php
@@ -231,6 +231,11 @@ class OC {
 				header("Location: $url");
 				exit();
 			}
+		} else {
+			// Invalidate HSTS headers
+			if (OC_Request::serverProtocol() === 'https') {
+				header('Strict-Transport-Security: max-age=0');
+			}
 		}
 	}
 
-- 
GitLab