diff --git a/.htaccess b/.htaccess index 8a98e89f..f00a7095 100644 --- a/.htaccess +++ b/.htaccess @@ -1,6 +1,14 @@ RewriteEngine on +# ----- Force HTTPS everywhere ----- +# Redirect any plain-http request to https. The two conditions together avoid +# a redirect loop when TLS is terminated by an upstream proxy (which forwards +# X-Forwarded-Proto: https while %{HTTPS} may read as off). +RewriteCond %{HTTPS} !=on +RewriteCond %{HTTP:X-Forwarded-Proto} !=https +RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L] + # ----- Language root redirect ----- # Send the bare root to the default-language homepage, on WHATEVER host is # serving the site (relative — no cross-domain redirect). Do NOT force @@ -74,6 +82,10 @@ Options -Indexes Header set X-Content-Type-Options "nosniff" + # HSTS: after the first HTTPS visit, browsers refuse plain HTTP for this + # host. Conservative 6-month max-age, no preload/includeSubDomains so it + # stays easy to adjust. (Ignored by browsers over plain HTTP — harmless.) + Header always set Strict-Transport-Security "max-age=15768000" # Clickjacking protection — the site should never be framed by other origins. Header always set X-Frame-Options "SAMEORIGIN" # Don't leak full page URLs to third parties (analytics, external links).