Improvements to TLS and primary domain redirects for non-static assets

Moved discussion to its own thread: Primary domain redirects do not support HSTS preload standard.