From 0c07b05b1fbb26210fbd0b8dc5975adb3d3df5ec Mon Sep 17 00:00:00 2001 From: popovskik Date: Tue, 4 Aug 2026 10:37:37 +0200 Subject: [PATCH] security(.htaccess): force HTTPS + add HSTS - Redirect all plain-http requests to https (double condition guards against a redirect loop behind a TLS-terminating proxy). - Add Strict-Transport-Security (6-month max-age, no preload/includeSubDomains so it stays easy to adjust) so browsers refuse http after the first visit. Closes the "HTTPS everywhere" gap: previously http:// served in the clear. Co-Authored-By: Claude Opus 4.8 (1M context) --- .htaccess | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/.htaccess b/.htaccess index 8a98e89f..f00a7095 100644 --- a/.htaccess +++ b/.htaccess @@ -1,6 +1,14 @@ RewriteEngine on +# ----- Force HTTPS everywhere ----- +# Redirect any plain-http request to https. The two conditions together avoid +# a redirect loop when TLS is terminated by an upstream proxy (which forwards +# X-Forwarded-Proto: https while %{HTTPS} may read as off). +RewriteCond %{HTTPS} !=on +RewriteCond %{HTTP:X-Forwarded-Proto} !=https +RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L] + # ----- Language root redirect ----- # Send the bare root to the default-language homepage, on WHATEVER host is # serving the site (relative — no cross-domain redirect). Do NOT force @@ -74,6 +82,10 @@ Options -Indexes Header set X-Content-Type-Options "nosniff" + # HSTS: after the first HTTPS visit, browsers refuse plain HTTP for this + # host. Conservative 6-month max-age, no preload/includeSubDomains so it + # stays easy to adjust. (Ignored by browsers over plain HTTP — harmless.) + Header always set Strict-Transport-Security "max-age=15768000" # Clickjacking protection — the site should never be framed by other origins. Header always set X-Frame-Options "SAMEORIGIN" # Don't leak full page URLs to third parties (analytics, external links).