aboutsummaryrefslogtreecommitdiffstats
path: root/actionpack/test
diff options
context:
space:
mode:
authorGrant Bourque <grant@anedot.com>2018-01-16 18:14:06 -0600
committerGrant Bourque <grant@anedot.com>2018-01-16 18:37:18 -0600
commit6f5cca77313e127313ea44c5c213fda3b9027a95 (patch)
tree5d30c79294cbbd7f038fa529a0f1dd918fb4a800 /actionpack/test
parent4c0cb1c2c9269c74588da9f114f52ea3707ae8fb (diff)
downloadrails-6f5cca77313e127313ea44c5c213fda3b9027a95.tar.gz
rails-6f5cca77313e127313ea44c5c213fda3b9027a95.tar.bz2
rails-6f5cca77313e127313ea44c5c213fda3b9027a95.zip
Update default HSTS max-age value to 1 year
- Update the default HSTS max-age value to 31536000 seconds (1 year) to meet the minimum max-age requirement for https://hstspreload.org/.
Diffstat (limited to 'actionpack/test')
-rw-r--r--actionpack/test/dispatch/ssl_test.rb4
1 files changed, 2 insertions, 2 deletions
diff --git a/actionpack/test/dispatch/ssl_test.rb b/actionpack/test/dispatch/ssl_test.rb
index 8ac9502af9..90f2ee46ea 100644
--- a/actionpack/test/dispatch/ssl_test.rb
+++ b/actionpack/test/dispatch/ssl_test.rb
@@ -98,8 +98,8 @@ class RedirectSSLTest < SSLTest
end
class StrictTransportSecurityTest < SSLTest
- EXPECTED = "max-age=15552000"
- EXPECTED_WITH_SUBDOMAINS = "max-age=15552000; includeSubDomains"
+ EXPECTED = "max-age=31536000"
+ EXPECTED_WITH_SUBDOMAINS = "max-age=31536000; includeSubDomains"
def assert_hsts(expected, url: "https://example.org", hsts: { subdomains: true }, headers: {})
self.app = build_app ssl_options: { hsts: hsts }, headers: headers