Changeset - 26bf9c8baad2
[Not reviewed]
beta
0 1 0
Marcin Kuzminski - 13 years ago 2013-01-27 22:37:55
marcin@python-works.com
added HSTS headers when using SSL for RhodeCode
1 file changed with 6 insertions and 1 deletions:
0 comments (0 inline, 0 general)
rhodecode/lib/middleware/https_fixup.py
Show inline comments
 
@@ -20,24 +20,29 @@
 
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 
# GNU General Public License for more details.
 
#
 
# You should have received a copy of the GNU General Public License
 
# along with this program.  If not, see <http://www.gnu.org/licenses/>.
 

	
 
from pylons.controllers.util import Request
 
from rhodecode.lib.utils2 import str2bool
 

	
 

	
 
class HttpsFixup(object):
 

	
 
    def __init__(self, app, config):
 
        self.application = app
 
        self.config = config
 

	
 
    def __call__(self, environ, start_response):
 
        self.__fixup(environ)
 
        return self.application(environ, start_response)
 
        req = Request(environ)
 
        resp = req.get_response(self.application)
 
        if environ['wsgi.url_scheme'] == 'https':
 
            resp.headers['Strict-Transport-Security'] = 'max-age=8640000; includeSubDomains'
 
        return resp(environ, start_response)
 

	
 
    def __fixup(self, environ):
 
        """
 
        Function to fixup the environ as needed. In order to use this
 
        middleware you should set this header inside your
 
        proxy ie. nginx, apache etc.
0 comments (0 inline, 0 general)