diff --git a/flask_sslify.py b/flask_sslify.py index 19dfeb8..fcbf21e 100644 --- a/flask_sslify.py +++ b/flask_sslify.py @@ -54,5 +54,6 @@ class SSLify(object): def set_hsts_header(self, response): """Adds HSTS header to each response.""" - response.headers.setdefault('Strict-Transport-Security', self.hsts_header) + if request.is_secure: + response.headers.setdefault('Strict-Transport-Security', self.hsts_header) return response