From bc5c064589b12aa532ac981461320cac4c6a6d0e Mon Sep 17 00:00:00 2001 From: Franz Sauerwald <15076254+FranzSw@users.noreply.github.com> Date: Tue, 8 Feb 2022 18:31:26 +0100 Subject: [PATCH] Set force_ssl=true (#268) (#269) Co-authored-by: NikkelM Co-authored-by: Nick Bessin <68278780+SinNeax@users.noreply.github.com> Co-authored-by: NikkelM --- config/environments/production.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/config/environments/production.rb b/config/environments/production.rb index 4514ca08..feb8193a 100644 --- a/config/environments/production.rb +++ b/config/environments/production.rb @@ -47,7 +47,7 @@ # config.action_cable.allowed_request_origins = [ 'http://example.com', /http:\/\/example.*/ ] # Force all access to the app over SSL, use Strict-Transport-Security, and use secure cookies. - # config.force_ssl = true + config.force_ssl = true # Include generic and useful information about system operation, but avoid logging too much # information to avoid inadvertent exposure of personally identifiable information (PII).