Hacker News new | ask | show | jobs
by kji 746 days ago
HSTS is intended for browsers. For API clients the correct behavior (following curl's lead) is probably to never follow/make any redirects by default.