Caught in Strict-Transport-Security


using brave from snap 1.60.118, running Ubuntu 23.10, I ran into that problem:

I was browsing a local application under http://localhost:3000/, working well. Due to some misconfiguration/configuration test, the application was set to set a Strict-Transport-Security header, although never offering TLS. Since then, brave insists on using TLS, even on the URL http://localhost:3000/, refuses to talk plaintext HTTP, thus cannot connect to the application anymore.

I did not find any setting in the settings, to reset or cancel this.

Not even deleting the files in ~/snap/brave/current/ actually helped.

So the question is:

How would one cancel Strict-Transport-Security settings for a particular URL/site?


This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.