Strict-Transport-Security not enforced
The application did not return an HSTS header. Without it, browsers do not enforce HTTPS-only access on first visit or after the policy expires, widening the window for SSL-stripping or downgrade attacks.
Description
The application did not return the Strict-Transport-Security header. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users, by rewriting HTTPS requests as HTTP.
Impact
Informational. Defense-in-depth gap rather than a directly exploitable bug.
Recommendation
Return Strict-Transport-Security: max-age=63072000; includeSubDomains; preload on all responses. Consider submitting the domain to the HSTS preload list once the policy has been stable for a few weeks.
Beecasino: Acknowledged. Zealynx: Acknowledged.