跳到主要内容

8. User Agent Processing Model (User Agent 处理模型)

UA 从 secure response 中接收有效的 Strict-Transport-Security header 后, 记录或更新该 host 的 HSTS state. 记录内容至少包括 host name, policy expiration time, 以及是否启用 includeSubDomains.

UA MUST 忽略通过 insecure transport 收到的 HSTS header. 对 Known HSTS Host 的 http URI dereference, UA MUST 在发起连接前将 scheme 改为 https. 如果 URI 中显式包含 port, UA 保留该 port; 若没有显式 port, 使用 https 的默认 port.

当连接 Known HSTS Host 时, UA MUST 将所有 secure transport error 或 warning 视为 fatal. 用户不能通过确认对话框继续访问. 这正是 HSTS 防止 click-through insecurity 的核心行为.

UA 在判断某 host 是否为 Known HSTS Host 时, 还要考虑父域是否记录了 includeSubDomains. 如果父域 policy 仍有效且覆盖子域, 子域也按 Known HSTS Host 处理.