All fixes

Add an HSTS header

headers-hsts

Without Strict-Transport-Security a browser still tries plain HTTP first, and one intercepted request is enough to steal a session cookie.

Cloudflare

  1. 1 Go to SSL/TLS > Edge Certificates
  2. 2 Scroll down to HTTP Strict Transport Security (HSTS)
  3. 3 Enable HSTS and set Max-Age to at least 12 months
  4. 4 Enable includeSubDomains if all subdomains use HTTPS
Header name: Strict-Transport-Security
Value: max-age=31536000; includeSubDomains
Cloudflare docs

Does your app still have this?

Scan your domain