Merge pull request #8 from nvie/master

Don't send HSTS headers over non-HTTPS connections
This commit is contained in:
2014-01-08 11:09:27 -08:00
+2 -1
View File
@@ -54,5 +54,6 @@ class SSLify(object):
def set_hsts_header(self, response):
"""Adds HSTS header to each response."""
response.headers.setdefault('Strict-Transport-Security', self.hsts_header)
if request.is_secure:
response.headers.setdefault('Strict-Transport-Security', self.hsts_header)
return response