Connect/Express middleware to enforce https using is-https.
Install package
yarn add redirect-ssl # or npm install redirect-sslRequire and use middleware (Make sure adding it as the first in the chain)
const redirectSSL = require('redirect-ssl')
// Add middleware
app.use(redirectSSL)
// Or if want to provide options
app.use(redirectSSL.create({ redirectPort: 8443 }))- Default:
true
Trust and check x-forwarded-proto header for HTTPS detection.
- Default:
443
Redirect users to this port for HTTPS. (:443 is omitted from URL as is default for https:// schema)
- Default:
undefined
Redirects using this value as host, if omitted will use request host for redirects.
NOTE It should not contain schema or trailing slashes. (Example: google.com)
- Default:
true
Redirect when no SSL detection method is available too. disable this option if you encounter redirect loops.
- Default:
307Temporary Redirect
Status code when redirecting. The reason of choosing 307 for default is:
- It prevents changing method from
POSTTOGETby user agents. (If you don't care, use302Found) - Is temporary so if for any reason HTTPS disables on server clients won't hurt. (If you need permanent, use
308Permanent Redirect or301Moved Permanently) - See This question, 307 on MDN, and RFC 7231 section 6.4.7 for more info.
MIT - Nuxt.js