zio-http
zio-http copied to clipboard
Add Support for Strict-Transport-Security (STS) Header
The Strict-Transport-Security (STS) header enforces secure HTTPS connections by instructing browsers to avoid using HTTP. Implementing the STS header in ZIO-HTTP would enhance security by preventing man-in-the-middle attacks and ensuring that communication remains encrypted.
Key Requirements:
- Implement support for the Strict-Transport-Security header.
- Support max-age, includeSubDomains and preload directives.
- Add tests to ensure compliance with the HTTP specifications regarding the STS header
Reference: https://datatracker.ietf.org/doc/html/rfc6797