The toy HSTS example keeps its boundary narrow.

highlighted = computed this step

What this toy model checks

The trust boundary parses one GET request, one response with Strict-Transport-Security, one max-age value, one remembered HTTPS row, and one empty body.

recompute HSTS rows\text{recompute HSTS rows}
HSTS honesty boundaryThe remembered HTTPS rule and empty response body are recomputed from the pinned HSTS response.HSTS honesty boundary - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

Honesty boundary

NOTE: toy HTTP HSTS header only; not browser preload lists, subdomain policy, HTTPS redirects, certificate validation, TLS internals, mixed content, private browsing, clock behavior, cache clearing, HTTP/2 or HTTP/3, frameworks, or production security config.

toy HSTS header only\text{toy HSTS header only}
HSTS honesty boundaryThe remembered HTTPS rule and empty response body are recomputed from the pinned HSTS response.HSTS honesty boundary - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

No client compute

The page shows already validated rows. It does not simulate browser storage.

static validated rows\text{static validated rows}
HSTS honesty boundaryThe remembered HTTPS rule and empty response body are recomputed from the pinned HSTS response.HSTS honesty boundary - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty

Summary

HSTS can tell a client to remember HTTPS for a duration, but this page only models one tiny header.

HSTS boundary checked\text{HSTS boundary checked}
HSTS honesty boundaryThe remembered HTTPS rule and empty response body are recomputed from the pinned HSTS response.HSTS honesty boundary - secure.example remembers HTTPS for 60 secondssectionnamevaluecheckrequest linemethodGETparsedrequest linepath/parsedrequest lineversionHTTP/1.1parsedheaderHostsecure.exampleexactheaderStrict-Transport-Securitymax-age=60exactdirectivenamemax-ageparseddirectiveseconds60integerremembered rulehostsecure.examplefrom requestremembered ruleruleHTTPSfrom HSTSremembered ruleseconds60max-agestatusversionHTTP/1.1parsedstatusstatus200 OKokheaderContent-Length0empty bodybodybyte length0countedcheckhostsecure.exampleexactcheckstatus200 OKokcheckmax-age60secondscheckremembered ruleHTTPS for 60 secondsderivedchecksent body bytes0empty